Yootheme develops the PageKit content management system, a narrowly focused product that has surfaced vulnerabilities centered on cross-site scripting and input-handling issues typical of web-application platforms. Treat this as a compact vendor profile rather than a broad trend line; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Yootheme over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-8070MEDIUM Open redirect vulnerability in YOOtheme Pagekit CMS 0.8.7 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the redirect pa | Oct 14, 2014 | 6.8 | 18 | NO | NO |
CVE-2014-8069MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in YOOtheme Pagekit CMS 0.8.7 allow remote attackers to inject arbitrary web script or HTML via the (1) HTTP Referer header to i | Oct 14, 2014 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Yootheme.
Media articles that mention a CVE ID that affects a product developed by Yootheme — matched by CVE ID, not by vendor name.