Themevolty develops a suite of CMS plugins and themes focused on e-commerce functionality, including payment processing, product display, and category management components that extend WordPress and similar platforms. Its vulnerability profile is dominated by SQL injection weaknesses across this product line, and the disclosures skew strongly toward critical-severity outcomes, while public exploit code has an elevated tendency to be associated with these flaws. Defenders should prioritize patching instances of these CMS components, particularly those exposed to untrusted input; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Themevolty over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-39650CRITICAL Theme Volty CMS Blog up to version v4.0.1 was discovered to contain a SQL injection vulnerability via the id parameter at /tvcmsblog/single. | Aug 28, 2023 | 9.8 | 38 | NO | YES |
CVE-2023-39651CRITICAL Improper neutralization of SQL parameter in Theme Volty CMS BrandList module for PrestaShop In the module “Theme Volty CMS BrandList” (tvcmsbrandlist) up to version 4.0.1 from Them | Oct 3, 2023 | 9.8 | 30 | NO | NO |
CVE-2023-27846CRITICAL SQL injection vulnerability found in PrestaShop themevolty v.4.0.8 and before allow a remote attacker to gain privileges via the tvcmsblog, tvcmsvideotab, tvcmswishlist, tvcmsbrand | Oct 31, 2023 | 9.8 | 27 | NO | NO |
CVE-2023-39647CRITICAL Improper neutralization of SQL parameter in Theme Volty CMS Category Product module for PrestaShop. In the module “Theme Volty CMS Category Product” (tvcmscategoryproduct) up to ve | Oct 3, 2023 | 9.8 | 26 | NO | NO |
CVE-2023-39649CRITICAL Improper neutralization of SQL parameter in Theme Volty CMS Category Slider module for PrestaShop. In the module “Theme Volty CMS Category Slider” (tvcmscategoryslider) up to versi | Oct 3, 2023 | 9.8 | 26 | NO | NO |
CVE-2023-39648CRITICAL Improper neutralization of SQL parameter in Theme Volty CMS Testimonial module for PrestaShop. In the module “Theme Volty CMS Testimonial” (tvcmstestimonial) up to version 4.0.1 fr | Oct 3, 2023 | 9.8 | 26 | NO | NO |
CVE-2023-39646CRITICAL Improper neutralization of SQL parameter in Theme Volty CMS Category Chain Slider module for PrestaShop. In the module “Theme Volty CMS Category Chain Slide"(tvcmscategorychainslid | Oct 3, 2023 | 9.8 | 26 | NO | NO |
CVE-2023-39645CRITICAL Improper neutralization of SQL parameter in Theme Volty CMS Payment Icon module for PrestaShop. In the module “Theme Volty CMS Payment Icon” (tvcmspaymenticon) up to version 4.0.1 | Oct 3, 2023 | 9.8 | 26 | NO | NO |
CVE-2023-39652CRITICAL theme volty tvcmsvideotab up to v4.0.0 was discovered to contain a SQL injection vulnerability via the component TvcmsVideoTabConfirmDeleteModuleFrontController::run(). | Aug 28, 2023 | 9.8 | 26 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Themevolty.
Media articles that mention a CVE ID that affects a product developed by Themevolty — matched by CVE ID, not by vendor name.