Thememove develops a portfolio of WordPress-based themes and plugins focused on educational, e-commerce, and specialized service platforms such as Edumall, Makeaholic, Minimog, Healsoul, and Maxcoach. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and recur through foundational web-application weakness classes including PHP remote file inclusion, missing authorization checks, and SQL injection—flaws endemic to plugin and theme development where input handling and access control are often inadequately secured. Defenders should treat Thememove-powered sites as requiring vigilant patching and code-review discipline; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Thememove over time
Signals from CVEs in this vendor scope (24 CVEs).
24 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-69094HIGH Subscriber SQL Injection in Unicamp <= 2.2.2 versions. | Jul 2, 2026 | 8.5 | 36 | NO | NO |
CVE-2025-22708CRITICAL Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Mitech mitech allows PHP Local File Inclusion.Thi | Jan 8, 2026 | 9.8 | 34 | NO | NO |
CVE-2025-22707CRITICAL Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Moody tm-moody allows PHP Local File Inclusion.Th | Jan 8, 2026 | 9.8 | 34 | NO | NO |
CVE-2025-14430CRITICAL Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Brook brook allows PHP Local File Inclusion.This | Jan 8, 2026 | 9.8 | 34 | NO | NO |
CVE-2025-14429CRITICAL Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove AeroLand aeroland allows PHP Local File Inclusion | Jan 8, 2026 | 9.8 | 34 | NO | NO |
CVE-2026-57790HIGH Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Billey billey allows PHP Local File Inclusion.Thi | Jul 13, 2026 | 7.5 | 33 | NO | NO |
CVE-2026-57791HIGH Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Brook brook allows PHP Local File Inclusion.This | Jul 13, 2026 | 7.5 | 32 | NO | NO |
CVE-2025-54701CRITICAL Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Unicamp unicamp allows PHP Local File Inclusion.T | Aug 14, 2025 | 9.8 | 30 | NO | NO |
CVE-2025-54700CRITICAL Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Makeaholic makeaholic allows PHP Local File Inclu | Aug 14, 2025 | 9.8 | 30 | NO | NO |
CVE-2025-58206CRITICAL Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove MaxCoach maxcoach allows PHP Local File Inclusion | Sep 5, 2025 | 9.8 | 29 | NO | NO |
Signals from CVEs in this vendor scope (24 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Thememove.
Media articles that mention a CVE ID that affects a product developed by Thememove — matched by CVE ID, not by vendor name.