PatchSiren

CodexThemes CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM CodexThemes CVE published 2026-07-23

CVE-2026-65480

CVE-2026-65480 is a Cross-site Scripting (XSS) vulnerability in the TheGem theme, allowing DOM-Based XSS. The issue affects TheGem versions from n/a before 5.12.1.1. This vulnerability has a CVSS score of 6.5 and a severity of MEDIUM. Users of TheGem theme versions prior to 5.12.1.1 should review and apply patches or updates to mitigate XSS attacks. Affected operators and security teams should assess pote [truncated]

HIGH CodexThemes CVE published 2026-07-13

CVE-2026-57804

CVE-2026-57804 is a PHP Local File Inclusion vulnerability in TheGem Theme Elements (for Elementor) due to improper control of filename for include/require statements. This issue affects TheGem Theme Elements (for Elementor) from n/a through <= 5.11.1 with a CVSS score of 7.5. The vulnerability allows attackers to include local files, potentially leading to code execution. Users of TheGem Theme Elements ( [truncated]