Undsgn's vulnerability profile concentrates in its Uncode web design and page-building product, with the durable signal centered on application-layer input-handling issues including improper input validation and cross-site scripting. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Undsgn over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-48107HIGH Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in undsgn Uncode uncode allows Reflected XSS.This issue affects Uncode: from n/a | Sep 26, 2025 | 7.1 | 24 | NO | NO |
CVE-2024-13691MEDIUM The Uncode theme for WordPress is vulnerable to arbitrary file read due to insufficient input validation in the 'uncode_recordMedia' function in all versions up to, and including, | Feb 18, 2025 | 6.5 | 19 | NO | NO |
CVE-2024-13681HIGH The Uncode theme for WordPress is vulnerable to arbitrary file read due to insufficient input validation in the 'uncode_admin_get_oembed' function in all versions up to, and includ | Feb 18, 2025 | 7.5 | 19 | NO | NO |
CVE-2023-51501MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Undsgn Uncode - Creative & WooCommerce WordPress Theme allows Reflected XSS.Th | Dec 28, 2023 | 6.1 | 18 | NO | NO |
CVE-2024-13667MEDIUM The Uncode theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘mle-description’ parameter in all versions up to, and including, 2.9.1.6 due to insufficient in | Feb 18, 2025 | 5.4 | 15 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Undsgn.
Media articles that mention a CVE ID that affects a product developed by Undsgn — matched by CVE ID, not by vendor name.