CVE-2020-36334: Themegrill Demo Importer

High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.

themegrill-demo-importer before 1.6.3 allows CSRF, as demonstrated by wiping the database.

Affected products

  • Themegrill Themegrill Demo Importer: before 1.6.3 (fixed in 1.6.3)

Published 2021-05-05. Last modified 2026-06-17.