Themeist's vulnerability footprint concentrates in a web application product called "I Recommend This," with exposure centering on application-layer input-handling and state-management issues including SQL injection, cross-site scripting, and cross-site request forgery. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Themeist over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-10376CRITICAL The i-recommend-this plugin before 3.7.3 for WordPress has SQL injection. | Aug 16, 2019 | 9.8 | 31 | NO | NO |
CVE-2014-125099CRITICAL A vulnerability has been found in I Recommend This Plugin up to 3.7.2 on WordPress and classified as critical. Affected by this vulnerability is an unknown functionality of the fil | Apr 20, 2023 | 9.8 | 30 | NO | NO |
CVE-2023-28696HIGH Cross-Site Request Forgery (CSRF) vulnerability in Harish Chouhan, Themeist I Recommend This allows Cross Site Request Forgery.This issue affects I Recommend This: from n/a through | Nov 12, 2023 | 8.8 | 25 | NO | NO |
CVE-2023-23673MEDIUM Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Harish Chouhan, Themeist I Recommend This plugin <= 3.8.3 versions. | May 16, 2023 | 4.8 | 19 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Themeist.
Media articles that mention a CVE ID that affects a product developed by Themeist — matched by CVE ID, not by vendor name.