Vulnerabilities
Summary — last 7 days
New vulnerabilities2,687▼ 646 vs. last week
Critical / high1,266▼ 292 vs. last week
New active exploitation (KEV)3▼ 5 vs. last week
Unscored (no CVSS)250▼ 252 vs. last week
1 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Analyzed | Medium (6.1) | 0.19% | — | Cyberfoxdigital Christmasify! | 8/12/2024 | 6/17/2026 | The Christmasify! plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.5. This is due to missing nonce validation on the 'options' function. This makes it possible for unauthenticated attackers to modify the plugin's settings and inject malicious web scripts via a… |