Ad

CVE-2026-27385

NONE EPSS 0.04%
Updated Mar 05, 2026
Parameter Value
Type CWE-79 (Cross-Site Scripting (XSS))
Public PoC No

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in designthemes DesignThemes Portfolio designthemes-portfolio allows Reflected XSS.This issue affects DesignThemes Portfolio: from n/a through <= 1.3.