Uxper's vulnerability footprint centers on a narrow product portfolio including the Civi and Golo platforms, with recurring exposure rooted in authentication and access-control weaknesses such as authentication bypass via alternate channels, missing authentication for critical functions, improper authorization, unrestricted file uploads, and hard-coded credentials. These patterns reflect common risks in web-facing and integration-oriented applications where authentication and input-handling boundaries require rigorous enforcement; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Uxper over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-54725CRITICAL Authentication Bypass Using an Alternate Path or Channel vulnerability in uxper Golo golo allows Authentication Abuse.This issue affects Golo: from n/a through <= 1.7.0. | Aug 28, 2025 | 9.8 | 34 | NO | NO |
CVE-2026-23975CRITICAL Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in uxper Golo golo allows PHP Local File Inclusion.This issue | Jan 22, 2026 | 9.8 | 33 | NO | NO |
CVE-2026-23974HIGH Missing Authorization vulnerability in uxper Golo golo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Golo: from n/a through < 1.7.5. | Jan 22, 2026 | 8.8 | 31 | NO | NO |
CVE-2020-23790CRITICAL An Arbitrary File Upload vulnerability was discovered in the Golo Laravel theme v 1.1.5. | May 12, 2021 | 9.8 | 31 | NO | NO |
CVE-2026-27051CRITICAL Incorrect Privilege Assignment vulnerability in uxper Golo golo allows Privilege Escalation.This issue affects Golo: from n/a through <= 1.7.0. | Mar 25, 2026 | 9.8 | 29 | NO | NO |
CVE-2024-12876CRITICAL The Golo - City Travel Guide WordPress Theme theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.6.10. This is du | Mar 7, 2025 | 9.8 | 28 | NO | NO |
CVE-2026-65476MEDIUM Unauthenticated Broken Access Control in Civi <= 2.2.4 versions. | Jul 23, 2026 | 5.3 | 25 | NO | NO |
CVE-2025-54724HIGH Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in uxper Golo golo allows Reflected XSS.This issue affects Golo: from n/a through | Aug 28, 2025 | 7.1 | 24 | NO | NO |
CVE-2026-23973HIGH Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in uxper Golo golo allows Reflected XSS.This issue affects Golo: from n/a through | Mar 25, 2026 | 7.1 | 23 | NO | NO |
CVE-2024-13773HIGH The Civi - Job Board & Freelance Marketplace WordPress Theme plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.4 via ha | Mar 14, 2025 | 7.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Uxper.
Media articles that mention a CVE ID that affects a product developed by Uxper — matched by CVE ID, not by vendor name.