Browse all 6 CVE security advisories affecting Blossomthemes. AI-powered Chinese analysis, POCs, and references for each vulnerability.
Blossomthemes develops WordPress themes and plugins for website building, with six CVEs recorded. Historically, vulnerabilities include stored cross-site scripting (XSS), arbitrary file uploads leading to remote code execution (RCE), and privilege escalation flaws, often stemming from insufficient input validation and improper access controls. Security assessments reveal inconsistent sanitization practices and inadequate user permission checks. While no major public incidents are documented, the pattern of vulnerabilities suggests ongoing challenges in secure coding practices. Users should implement strict input validation and keep installations updated to mitigate risks associated with these themes.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2024-37102 | WordPress Vilva theme <= 1.2.2 - Cross Site Request Forgery (CSRF) vulnerability — VilvaCWE-352 | 4.3 | Medium | 2025-01-02 |
This page lists every published CVE security advisory associated with Blossomthemes. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.