Cross-Site Request Forgery (CSRF) vulnerability in LOOS,Inc. Arkhe allows PHP Local File Inclusion. This issue affects Arkhe: from n/a through 3.11.0.
We have discovered 674 live websites that are affected by CVE-2025-26748.
| Product | |
| Category | Wordpress Themes |
| Vulnerable Domains | 674 live websites (100% of Arkhe install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 0 versions ( less than 0.1% of all versions) |
| 22 websites | |
| 588 websites | |
| 3 websites | |
| 2 websites | |
| 1 websites | |
| 1 websites | |
| 1 websites | |
| 1 websites | |
| 1 websites |
| .com | 321 websites |
| .jp | 148 websites |
| .co.jp | 77 websites |
| .net | 52 websites |
| .org | 21 websites |
| .info | 11 websites |
| .ru | 2 websites |
| .be | 1 websites |
| .ca | 1 websites |
| .co.uk | 1 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ***********.com | ***,*** | ||
| **********.com | ***,*** | ||
| ****************.com | ***,*** | ||
| **********.**.jp | ***,*** | ||
| ************.com | ***,*** | ||
| ****.**.jp | ***,*** | ||
| ********.**.jp | *,***,*** | ||
| **************.*******.**.jp | *,***,*** | ||
| *************.jp | *,***,*** | ||
| **********.org | *,***,*** |
FAQ