Aggregates CVE and security vulnerability intelligence across all blossomthemes-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.
Common weakness patterns include vendor risk csrf, vendor risk cross-site scripting, and vendor risk ssrf, with potential vendor impact session compromise across vendor surface software deployment use cases.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2024-37412 | Cross-Site Request Forgery (CSRF) vulnerability in blossomthemes Blossom Shop blossom-shop allows Cross Site Request Forgery.This issue affects Blossom Shop: from n/a through <= 1.1.7. | [email protected] | 4.3 | 0.22% | 2025-01-02 | 2026-06-17 |
| CVE-2024-37243 | Cross-Site Request Forgery (CSRF) vulnerability in blossomthemes Vandana Lite vandana-lite allows Cross Site Request Forgery.This issue affects Vandana Lite: from n/a through <= 1.1.9. | [email protected] | 4.3 | 0.16% | 2025-01-02 | 2026-06-17 |
| CVE-2024-37102 | Cross-Site Request Forgery (CSRF) vulnerability in blossomthemes Vilva vilva allows Cross Site Request Forgery.This issue affects Vilva: from n/a through <= 1.2.2. | [email protected] | 4.3 | 0.22% | 2025-01-02 | 2026-06-17 |
| CVE-2024-37098 | Server-Side Request Forgery (SSRF) vulnerability in Blossom Themes BlossomThemes Email Newsletter.This issue affects BlossomThemes Email Newsletter: from n/a through 2.2.6. | [email protected] | 4.4 | 0.28% | 2024-06-26 | 2026-06-17 |
| CVE-2024-31429 | Cross-Site Request Forgery (CSRF) vulnerability in Blossom Themes Sarada Lite.This issue affects Sarada Lite: from n/a through 1.1.2. | [email protected] | 4.3 | 0.16% | 2024-04-15 | 2026-06-17 |
| CVE-2024-2107 | The Blossom Spa theme for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.3.3 via generated source. This makes it possible for unauthenticated attackers to extract sensitive data including contents of password-protected or scheduled posts. | [email protected] | 5.8 | 0.47% | 2024-03-12 | 2026-06-17 |
| CVE-2022-37338 | Multiple Authenticated (contributor+) Stored Cross-Site Scripting (XSS) vulnerabilities in Blossom Recipe Maker plugin <= 1.0.7 at WordPress. | [email protected] | 4.1 | 0.41% | 2022-09-23 | 2026-06-17 |