Uxthemes maintains a focused WordPress theme product portfolio, with the Flatsome theme representing a widely adopted component in WordPress-based storefronts and publishing sites. Its vulnerability exposure concentrates on web-application input-handling and data-processing flaws, specifically cross-site scripting and deserialization of untrusted data, which are characteristic of server-side theme and plugin code. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Uxthemes over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-57729HIGH Missing Authorization vulnerability in UX-themes Flatsome flatsome allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Flatsome: from n/a thr | Jul 13, 2026 | 7.5 | 33 | NO | NO |
CVE-2026-57728HIGH Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in UX-themes Flatsome flatsome allows Reflected XSS.This issue affects Flatsome: | Jul 13, 2026 | 7.1 | 32 | NO | NO |
CVE-2023-40555CRITICAL Deserialization of Untrusted Data vulnerability in UX-themes Flatsome | Multi-Purpose Responsive WooCommerce Theme.This issue affects Flatsome | Multi-Purpose Responsive WooCommerc | Dec 20, 2023 | 9.8 | 29 | NO | NO |
CVE-2026-57731MEDIUM Contributor Broken Access Control in Flatsome <= 3.20.5 versions. | Jul 2, 2026 | 6.5 | 27 | NO | NO |
CVE-2026-57730MEDIUM Subscriber Broken Access Control in Flatsome <= 3.20.5 versions. | Jul 2, 2026 | 4.3 | 24 | NO | NO |
CVE-2026-28083MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in UX-themes Flatsome flatsome allows Stored XSS.This issue affects Flatsome: fro | Feb 26, 2026 | 6.5 | 22 | NO | NO |
CVE-2025-8684MEDIUM The Flatsome Theme for WordPress is vulnerable to Stored Cross-Site Scripting via the theme's shortcodes in all versions up to, and including, 3.20.0 due to insufficient input sani | Sep 5, 2025 | 6.4 | 20 | NO | NO |
CVE-2026-31915MEDIUM Missing Authorization vulnerability in UX-themes Flatsome flatsome allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Flatsome: from n/a thr | Mar 13, 2026 | 5.3 | 19 | NO | NO |
CVE-2024-5156MEDIUM The Flatsome theme for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 3.18.7 due to insufficient input s | Jun 20, 2024 | 6.4 | 18 | NO | NO |
CVE-2023-28994MEDIUM Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in UX-themes Flatsome plugin <= 3.16.8 versions. | Aug 23, 2023 | 6.1 | 18 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Uxthemes.
Media articles that mention a CVE ID that affects a product developed by Uxthemes — matched by CVE ID, not by vendor name.