Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Thememove

First CVE: Mar 14, 2022Active for: 4 yearsTotal CVEs: 24
43.4
VTI Score
High

Thememove develops a portfolio of WordPress-based themes and plugins focused on educational, e-commerce, and specialized service platforms such as Edumall, Makeaholic, Minimog, Healsoul, and Maxcoach. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and recur through foundational web-application weakness classes including PHP remote file inclusion, missing authorization checks, and SQL injection—flaws endemic to plugin and theme development where input handling and access control are often inadequately secured. Defenders should treat Thememove-powered sites as requiring vigilant patching and code-review discipline; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
24
Total CVEs
More Total CVEs than 97% of tracked vendors
0.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 5% of tracked vendors
8.4
Avg CVSS Score
Higher Avg CVSS Score than 81% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Thememove over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 14, 2022
4 years ago
Most Recent CVE
Jul 13, 2026
11 days ago

Products(16 total)

Top CVEs

Signals from CVEs in this vendor scope (24 CVEs).

24 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-69094HIGH
Subscriber SQL Injection in Unicamp <= 2.2.2 versions.
Jul 2, 20268.536NONO
CVE-2025-22708CRITICAL
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Mitech mitech allows PHP Local File Inclusion.Thi
Jan 8, 20269.834NONO
CVE-2025-22707CRITICAL
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Moody tm-moody allows PHP Local File Inclusion.Th
Jan 8, 20269.834NONO
CVE-2025-14430CRITICAL
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Brook brook allows PHP Local File Inclusion.This
Jan 8, 20269.834NONO
CVE-2025-14429CRITICAL
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove AeroLand aeroland allows PHP Local File Inclusion
Jan 8, 20269.834NONO
CVE-2026-57790HIGH
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Billey billey allows PHP Local File Inclusion.Thi
Jul 13, 20267.533NONO
CVE-2026-57791HIGH
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Brook brook allows PHP Local File Inclusion.This
Jul 13, 20267.532NONO
CVE-2025-54701CRITICAL
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Unicamp unicamp allows PHP Local File Inclusion.T
Aug 14, 20259.830NONO
CVE-2025-54700CRITICAL
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Makeaholic makeaholic allows PHP Local File Inclu
Aug 14, 20259.830NONO
CVE-2025-58206CRITICAL
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove MaxCoach maxcoach allows PHP Local File Inclusion
Sep 5, 20259.829NONO
View all 24 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products24 CVEs
8%
54%
38%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network24 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low14 (58.3%)
High10 (41.7%)
Unknown0 (0.0%)
User Interaction
None23 (95.8%)
Unknown0 (0.0%)
Required1 (4.2%)
Privileges Required
Low8 (33.3%)
High0 (0.0%)
None16 (66.7%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (24 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Thememove.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Thememove — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Thememove's Products

View all 2 CNAs →

Top CWEs