PT-2026-35398 · Codexthemes · Thegem Theme Elements

João Pedro S Alcântara

+1

·

Published

2026-04-27

·

Updated

2026-04-27

·

CVE-2026-42410

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions CodexThemes TheGem Theme Elements (for Elementor) versions prior to 5.12.1.1
Description Improper neutralization of input during web page generation allows for DOM-Based Cross-Site Scripting (XSS), a flaw where an application contains client-side JavaScript that processes data from an untrusted source in an unsafe way, typically updating the Document Object Model (DOM).
Recommendations Update to version 5.12.1.1.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-42410

Affected Products

Thegem Theme Elements