Rockettheme develops a portfolio of Joomla extensions and templates, including products such as RokModule, RokDownloads, and the Gantry framework, that extend functionality for content management and site presentation. The vulnerabilities associated with this vendor center on application-layer input handling, recuring through SQL injection, path traversal, and cross-site scripting weaknesses that are characteristic of web-facing extensible platforms. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Rockettheme over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2010-1056MEDIUM Directory traversal vulnerability in the RokDownloads (com_rokdownloads) component before 1.0.1 for Joomla! allows remote attackers to include and execute arbitrary local files via | Mar 23, 2010 | 6.8 | 39 | NO | YES |
CVE-2010-1479HIGH SQL injection vulnerability in the RokModule (com_rokmodule) component 1.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the moduleid parameter in a raw | Apr 19, 2010 | 7.5 | 30 | NO | YES |
CVE-2010-1480HIGH SQL injection vulnerability in the RokModule (com_rokmodule) component 1.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the module parameter to index.p | Apr 19, 2010 | 7.5 | 29 | NO | YES |
CVE-2024-9382MEDIUM The Gantry 4 Framework plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'override_id' parameter in all versions up to, and including, 4.1.21 due to insu | Oct 18, 2024 | 6.1 | 19 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Rockettheme.
Media articles that mention a CVE ID that affects a product developed by Rockettheme — matched by CVE ID, not by vendor name.