Themenectar's vulnerability footprint centers on its Salient Core product, a web-facing application where the observed weakness class reflects input-handling challenges characteristic of web application development. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Themenectar over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-3812HIGH The Salient Core plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.0.7 via the 'nectar_icon' shortcode 'icon_linea' attribute. This | May 18, 2024 | 7.5 | 22 | NO | NO |
CVE-2023-48748MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Theme nectar Salient Core allows Reflected XSS.This issue affects Salient Core | Nov 30, 2023 | 6.1 | 18 | NO | NO |
CVE-2025-59001MEDIUM Missing Authorization vulnerability in ThemeNectar Salient Core salient-core allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Salient Core | Dec 16, 2025 | 4.3 | 17 | NO | NO |
CVE-2023-48749MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Theme nectar Salient Core allows Stored XSS.This issue affects Salient Core: f | Nov 30, 2023 | 5.4 | 16 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Themenectar.
Media articles that mention a CVE ID that affects a product developed by Themenectar — matched by CVE ID, not by vendor name.