PT-2026-21233 · Themegoods · Photome

João Pedro S Alcântara

+1

·

Published

2026-02-20

·

Updated

2026-02-20

·

CVE-2026-24949

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions ThemeGoods PhotoMe versions through 5.7.1
Description The software contains a flaw related to improper input handling during web page generation, leading to a DOM-Based Cross-site Scripting (XSS) condition. This allows for potential malicious code execution within the context of the user's browser.
Recommendations Update ThemeGoods PhotoMe to a version newer than 5.7.1.

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-24949

Affected Products

Photome