theme

Jannah Vulnerabilities

14 known security issues reported for the Jannah WordPress theme. Most recent disclosed Mar 16, 2026.

6 high 2 medium

Running Jannah on your site? Check whether your installed version is affected.

Scan your site free

Jannah - Local File Inclusion vulnerability

high

Local File Inclusion vulnerability

CVSS:
8.1
Affected:
up to 7.6.3
Fix:
No patched version reported
Disclosed:
Mar 16, 2026

Jannah - Newspaper Magazine News BuddyPress AMP <= 7.6.4 - Unauthenticated Local File Inclusion

high

The Jannah - Newspaper Magazine News BuddyPress AMP theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 7.6.4. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This ca...

CVSS:
8.1
Affected:
up to 7.6.4
Fixed in:
7.6.5
Disclosed:
Mar 16, 2026

CVE-2026-25464 on NVD →

Jannah [jannah] <= 7.6.0 (unfixed)

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in TieLabs Jannah jannah allows DOM-Based XSS.This issue affects Jannah: from n/a through <= 7.6.0.

Affected:
up to 7.6.0
Fix:
No patched version reported
Disclosed:
Dec 18, 2025

CVE-2025-64207 on NVD →

Jannah [jannah] <= 7.6.0 (unfixed)

unknown

[en] Deserialization of Untrusted Data vulnerability in TieLabs Jannah jannah allows Object Injection.This issue affects Jannah: from n/a through <= 7.6.0.

Affected:
up to 7.6.0
Fix:
No patched version reported
Disclosed:
Dec 18, 2025

CVE-2025-64206 on NVD →

Jannah [jannah] <= 7.6.0 (unfixed)

unknown

[en] Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in TieLabs Jannah jannah allows PHP Local File Inclusion.This issue affects Jannah: from n/a through <= 7.6.0.

Affected:
up to 7.6.0
Fix:
No patched version reported
Disclosed:
Dec 18, 2025

CVE-2025-64205 on NVD →

Jannah <= 7.6.0 - Unauthenticated Local File Inclusion

high

The Jannah theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 7.6.0. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obta...

CVSS:
8.1
Affected:
up to 7.6.0
Fixed in:
7.6.1
Disclosed:
Oct 29, 2025

CVE-2025-64205 on NVD →

Jannah <= 7.6.0 - Unauthenticated PHP Object Injection

high

The Jannah theme for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 7.6.0 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via an add...

CVSS:
8.1
Affected:
up to 7.6.0
Fixed in:
7.6.1
Disclosed:
Oct 29, 2025

CVE-2025-64206 on NVD →

Jannah <= 7.6.0 - Unauthenticated Stored Cross-Site Scripting

high

The Jannah theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 7.6.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an inje...

CVSS:
7.2
Affected:
up to 7.6.0
Fixed in:
7.6.1
Disclosed:
Oct 29, 2025

CVE-2025-64207 on NVD →

Jannah [jannah] <= 7.4.1 (unfixed)

unknown

[en] Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in TieLabs Jannah allows PHP Local File Inclusion. This issue affects Jannah: from n/a through 7.4.1.

Affected:
up to 7.4.1
Fix:
No patched version reported
Disclosed:
Aug 28, 2025

CVE-2025-53334 on NVD →

Jannah < 7.5.1 - Unauthenticated Local File Inclusion

high

The Jannah theme for WordPress is vulnerable to Local File Inclusion in versions up to, and excluding, 7.5.1. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obta...

CVSS:
8.1
Affected:
up to 7.5.1
Fixed in:
7.5.1
Disclosed:
Aug 25, 2025

CVE-2025-53334 on NVD →

Jannah [jannah] < 5.4.5

unknown

[en] The Jannah WordPress theme before 5.4.5 did not properly sanitize the 'query' POST parameter in its tie_ajax_search AJAX action, leading to a Reflected Cross-site Scripting (XSS) vulnerability.

Affected:
up to 5.4.5
Fixed in:
5.4.5
Disclosed:
Jul 6, 2021

CVE-2021-24407 on NVD →

Jannah [jannah] < 5.4.4

unknown

[en] The Jannah WordPress theme before 5.4.4 did not properly sanitize the options JSON parameter in its tie_get_user_weather AJAX action before outputting it back in the page, leading to a Reflected Cross-Site Scripting (XSS) vulnerability.

Affected:
up to 5.4.4
Fixed in:
5.4.4
Disclosed:
Jun 21, 2021

CVE-2021-24364 on NVD →

Jannah <= 5.4.4 - Reflected Cross-Site Scripting

medium

The Jannah WordPress theme before 5.4.5 did not properly sanitize the 'query' POST parameter in its tie_ajax_search AJAX action, leading to a Reflected Cross-site Scripting (XSS) vulnerability.

CVSS:
6.1
Affected:
up to 5.4.5
Fixed in:
5.4.5
Disclosed:
Jun 14, 2021

CVE-2021-24407 on NVD →

Jannah - Newspaper Magazine News BuddyPress AMP < 5.4.4 - Reflected Cross-Site Scripting

medium

The Jannah WordPress theme before 5.4.4 did not properly sanitize the options JSON parameter in its tie_get_user_weather AJAX action before outputting it back in the page, leading to a Reflected Cross-Site Scripting (XSS) vulnerability.

CVSS:
6.1
Affected:
up to 5.4.4
Fixed in:
5.4.4
Disclosed:
Jun 7, 2021

CVE-2021-24364 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database