Themescoder develops a web design and theming application with a modestly scoped product footprint centered on Themes Coder. The vendor's observed vulnerability exposure reflects input-handling weaknesses, particularly SQL injection in the application layer, which is characteristic of web-facing content-management and templating platforms. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Themescoder over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-13726HIGH The Coder WordPress plugin through 1.3.4 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated user | Feb 17, 2025 | 8.6 | 38 | NO | YES |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Themescoder.
Media articles that mention a CVE ID that affects a product developed by Themescoder — matched by CVE ID, not by vendor name.