Vulnerabilidades en LoftOcean
9 resultadosAnálisis Vexday
LoftOcean apresenta footprint reduzido com 8 CVEs catalogados, dos quais 3 são críticas, mas nenhuma encontra-se sob exploração ativa conhecida. A ausência de divulgações recentes (últimos 90 dias) sugere risco estabilizado, embora a fraqueza dominante CWE-98 (Injeção de Código) merça monitoramento continuado em futuras atualizações do produto.
CVE-2025-49454HIGHWordPress TinySalt theme < 3.10.0 - Local File Inclusion vulnerabilityEPSS 0.8%CVE-2024-13410CRITICALCozyStay <= 1.7.0 and TinySalt <= 3.9.0 - Unauthenticated PHP Object Injection in ajax_handlerEPSS 0.8%CVE-2025-49507CRITICALWordPress CozyStay theme < 1.7.1 - PHP Object Injection vulnerabilityEPSS 0.6%CVE-2025-49508HIGHWordPress CozyStay theme < 1.7.1 - Local File Inclusion vulnerabilityEPSS 0.6%CVE-2025-67988HIGHWordPress CozyStay theme < 1.9.1 - Local File Inclusion vulnerabilityEPSS 0.6%CVE-2025-67992HIGHWordPress PatioTime theme < 2.1 - Local File Inclusion vulnerabilityEPSS 0.5%CVE-2025-67995CRITICALWordPress PatioTime theme < 2.1 - PHP Object Injection vulnerabilityEPSS 0.5%CVE-2024-13412HIGHCozyStay <= 1.7.0 - Missing Authorization to Arbitrary Action Execution in ajax_handlerEPSS 0.3%CVE-2026-78289HIGHWordPress CozyStay theme <= 1.10.0 - Cross Site Scripting (XSS) vulnerabilityEPSS 0.2%