Browse all 18 CVE security advisories affecting themepoints. AI-powered Chinese analysis, POCs, and references for each vulnerability.
Themepoints is a digital experience platform enabling organizations to create and manage branded web applications and portals. Historically, the platform has been susceptible to multiple remote code execution vulnerabilities, cross-site scripting flaws, and privilege escalation issues, contributing to its 18 recorded CVEs. Security researchers have frequently identified authentication bypass weaknesses and insecure direct object references in its components. While no major public security incidents have been widely documented, the consistent pattern of vulnerabilities across different versions suggests potential risks for organizations relying on the platform without rigorous patch management and security hardening.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2024-12699 | Service Box <= 1.9 - Authenticated (Contributor+) Stored Cross-Site Scripting — Service BoxCWE-79 | 6.4 | Medium | 2025-01-07 |
This page lists every published CVE security advisory associated with themepoints. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.