Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Themevolty

First CVE: Aug 28, 2023Active for: 3 yearsTotal CVEs: 9

Themevolty develops a suite of CMS plugins and themes focused on e-commerce functionality, including payment processing, product display, and category management components that extend WordPress and similar platforms. Its vulnerability profile is dominated by SQL injection weaknesses across this product line, and the disclosures skew strongly toward critical-severity outcomes, while public exploit code has an elevated tendency to be associated with these flaws. Defenders should prioritize patching instances of these CMS components, particularly those exposed to untrusted input; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
9
Total CVEs
More Total CVEs than 91% of tracked vendors
1.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 74% of tracked vendors
9.8
Avg CVSS Score
Higher Avg CVSS Score than 91% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Themevolty over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 28, 2023
2 years ago
Most Recent CVE
Oct 31, 2023
997 days ago

Products(8 total)

Top CVEs

Signals from CVEs in this vendor scope (9 CVEs).

9 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-39650CRITICAL
Theme Volty CMS Blog up to version v4.0.1 was discovered to contain a SQL injection vulnerability via the id parameter at /tvcmsblog/single.
Aug 28, 20239.838NOYES
CVE-2023-39651CRITICAL
Improper neutralization of SQL parameter in Theme Volty CMS BrandList module for PrestaShop In the module “Theme Volty CMS BrandList” (tvcmsbrandlist) up to version 4.0.1 from Them
Oct 3, 20239.830NONO
CVE-2023-27846CRITICAL
SQL injection vulnerability found in PrestaShop themevolty v.4.0.8 and before allow a remote attacker to gain privileges via the tvcmsblog, tvcmsvideotab, tvcmswishlist, tvcmsbrand
Oct 31, 20239.827NONO
CVE-2023-39647CRITICAL
Improper neutralization of SQL parameter in Theme Volty CMS Category Product module for PrestaShop. In the module “Theme Volty CMS Category Product” (tvcmscategoryproduct) up to ve
Oct 3, 20239.826NONO
CVE-2023-39649CRITICAL
Improper neutralization of SQL parameter in Theme Volty CMS Category Slider module for PrestaShop. In the module “Theme Volty CMS Category Slider” (tvcmscategoryslider) up to versi
Oct 3, 20239.826NONO
CVE-2023-39648CRITICAL
Improper neutralization of SQL parameter in Theme Volty CMS Testimonial module for PrestaShop. In the module “Theme Volty CMS Testimonial” (tvcmstestimonial) up to version 4.0.1 fr
Oct 3, 20239.826NONO
CVE-2023-39646CRITICAL
Improper neutralization of SQL parameter in Theme Volty CMS Category Chain Slider module for PrestaShop. In the module “Theme Volty CMS Category Chain Slide"(tvcmscategorychainslid
Oct 3, 20239.826NONO
CVE-2023-39645CRITICAL
Improper neutralization of SQL parameter in Theme Volty CMS Payment Icon module for PrestaShop. In the module “Theme Volty CMS Payment Icon” (tvcmspaymenticon) up to version 4.0.1
Oct 3, 20239.826NONO
CVE-2023-39652CRITICAL
theme volty tvcmsvideotab up to v4.0.0 was discovered to contain a SQL injection vulnerability via the component TvcmsVideoTabConfirmDeleteModuleFrontController::run().
Aug 28, 20239.826NONO
View all 9 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products9 CVEs
100%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
Critical
Attack Vector
Local0 (0.0%)
Network9 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None9 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None9 (100.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (9 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
11.1% of CVEs· 96th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Themevolty.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Themevolty — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Themevolty's Products

View all 1 CNAs →

Top CWEs