Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Jupiter X Core — Vulnerabilities & Security Advisories 13

All 13 CVE vulnerabilities found in Jupiter X Core, with AI-generated Chinese analysis, references, and POCs.

Jupiter X Core is a WordPress theme developed by Brainstorm Force that is associated with multiple vulnerability classifications. This page aggregates known security weaknesses, including cross-site scripting, insecure direct object references, and authentication bypasses, covering reports published between 2021 and 2024. By reviewing the compiled data here, you can effectively track a vendor's security advisories as they are issued, gain a deeper understanding of specific weakness classes within the context of theme development, or look up a product's comprehensive vulnerability history to assess long-term maintenance practices. The collection includes both confirmed patches and unmitigated risks, providing a chronological view of how security issues have been identified and resolved over time. This resource is designed for security researchers, developers, and website administrators who need to evaluate the risk profile of the Jupiter X Core theme. Understanding these patterns helps in making informed decisions about plugin updates, code reviews, and migration strategies. The data reflects information gathered from public advisories, GitHub repositories, and community reports, ensuring a broad perspective on the security posture of the software. Users are encouraged to consult official sources for the most current mitigation steps, as this page serves primarily as a historical and analytical reference point.

Vendor: ArtBees

CVE IDTitleCVSSSeverityPublished
CVE-2026-3533 JupiterX Core <= 4.14.1 - Authenticated (Subscriber+) Missing Authorization To Limited File Upload via Popup Template Import CWE-434 8.8 High2026-03-23
CVE-2025-3888 Jupiterx Core <= 4.8.12 - Authenticated (Contributor+) Stored Cross-Site Scripting via Inline SVG CWE-79 6.4 Medium2025-05-17
CVE-2025-2105 Jupiter X Core <= 4.8.11 - Unauthenticated PHP Object Injection via PHAR CWE-502 8.1 High2025-04-26
CVE-2025-0365 Jupiterx Core <= 4.8.7 - Authenticated (Contributor+) Arbitrary File Read CWE-22 6.5 Medium2025-02-01
CVE-2025-0366 Jupiter X Core <= 4.8.7 - Authenticated (Contributor+) SVG Upload to Local File Inclusion (Remote Code Execution) CWE-98 8.8 High2025-02-01
CVE-2024-12316 Jupiter X Core <= 4.8.5 - Missing Authorization to Unauthenticated Popup Template Export CWE-862 5.3 Medium2025-01-07
CVE-2024-12033 Jupiter X Core <= 4.8.5 - Missing Authorization to Authenticated Library Sync CWE-862 4.3 Medium2025-01-07
CVE-2024-7781 Jupiter X Core <= 4.7.5 - Limited Unauthenticated Authentication Bypass to Account Takeover CWE-288 8.1 High2024-09-26
CVE-2024-7772 Jupiter X Core <= 4.6.5 - Unauthenticated Arbitrary File Upload CWE-434 9.8 Critical2024-09-26
CVE-2023-3813 Jupiter X Core <= 4.6.6 - Unauthenticated Arbitrary File Download CWE-22 7.5 High2023-07-21
CVE-2022-1659 JupiterX Core <= 2.0.6 - Information Disclosure, Modification, and Denial of Service CWE-284 5.4 Medium2022-06-13
CVE-2022-1654 Jupiter Theme <= 6.10.1 and JupiterX Core Plugin <= 2.0.7 - Authenticated Privilege Escalation CWE-269 8.8 High2022-06-13
CVE-2022-1656 JupiterX Theme <= 2.0.6 and JupiterX Core <= 2.0.6 - Authenticated Arbitrary Plugin Deactivation and Settings Modification CWE-284 5.4 Medium2022-06-13

All 13 known CVE vulnerabilities affecting Jupiter X Core with full Chinese analysis, references, and POCs where available.