Select Themes maintains a narrow product portfolio centered on the Stockholm and Stockholm Core offerings, which serve a specialized role in a focused market segment. Current exploitation activity, severity breakdown, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Select Themes over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-34551CRITICAL Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Select-Themes Stockholm allows PHP Local File Inclusion.This issue affects Stockholm | Jun 4, 2024 | 9.8 | 27 | NO | NO |
CVE-2025-68068HIGH Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Select-Themes Stockholm stockholm allows PHP Local File Inc | Dec 16, 2025 | 7.5 | 25 | NO | NO |
CVE-2025-68067HIGH Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Select-Themes Stockholm Core stockholm-core allows PHP Loca | Dec 16, 2025 | 7.5 | 24 | NO | NO |
CVE-2024-34554HIGH Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Select-Themes Stockholm Core allows PHP Local File Inclusion.This issue affects Stoc | Jun 4, 2024 | 8.8 | 24 | NO | NO |
CVE-2024-34552HIGH Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Select-Themes Stockholm allows PHP Local File Inclusion.This issue affects Stockholm | Jun 4, 2024 | 8.8 | 24 | NO | NO |
CVE-2025-68077MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Select-Themes Stockholm stockholm allows Stored XSS.This issue affects Stockho | Dec 16, 2025 | 6.5 | 21 | NO | NO |
CVE-2025-68076MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Select-Themes Stockholm Core stockholm-core allows Stored XSS.This issue affec | Dec 16, 2025 | 6.5 | 20 | NO | NO |
CVE-2024-34553MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Select-Themes Stockholm Core allows Reflected XSS.This issue affects Stockholm | May 8, 2024 | 6.1 | 19 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Select Themes.
Media articles that mention a CVE ID that affects a product developed by Select Themes — matched by CVE ID, not by vendor name.