---
id: CVE-2009-10004
title: A vulnerability was found in Turante Sandbox Theme up to 1.5.2
summary: >-
  A vulnerability was found in Turante Sandbox Theme up to 1.5.2. It has been
  classified as problematic. This affects the function sandbox_body_class of the
  file functions.php. The manipulation of the argument page leads to cross site
  scri…
severity: low
cvss: 3.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N'
cwe:
  - CWE-79
vendor: sandbox_theme_project
product: sandbox_theme
affected:
  - sandbox_theme < 1.6.1
patched:
  - sandbox_theme 1.6.1
published: '2023-04-10'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T23:10:00.233'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2009-10004'
references:
  - url: >-
      https://github.com/Turante/sandbox-theme/commit/8045b1e10970342f558b2c5f360e0bd135af2b10
    label: cna@vuldb.com
  - url: 'https://github.com/Turante/sandbox-theme/releases/tag/1.6.1'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?ctiid.225357'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?id.225357'
    label: cna@vuldb.com
  - url: >-
      https://github.com/Turante/sandbox-theme/commit/8045b1e10970342f558b2c5f360e0bd135af2b10
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://github.com/Turante/sandbox-theme/releases/tag/1.6.1'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://vuldb.com/?ctiid.225357'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://vuldb.com/?id.225357'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.0053
epssPercentile: 0.42742
ingestedAt: '2026-10-02T00:04:54.708Z'
---

## Overview

A vulnerability was found in Turante Sandbox Theme up to 1.5.2. It has been classified as problematic. This affects the function sandbox_body_class of the file functions.php. The manipulation of the argument page leads to cross site scripting. It is possible to initiate the attack remotely. Upgrading to version 1.6.1 is able to address this issue. The identifier of the patch is 8045b1e10970342f558b2c5f360e0bd135af2b10. It is recommended to upgrade the affected component. The identifier VDB-225357 was assigned to this vulnerability.

## Affected

- `sandbox_theme < 1.6.1`

## Remediation

Upgrade past the affected range:

- `sandbox_theme 1.6.1`
