Vulnerabilidades en axiomthemes

98 resultados
Análisis Vexday

O portfólio de vulnerabilidades da AxiomThemes reúne 85 CVEs catalogadas, das quais 7 são classificadas como críticas — um volume que merece atenção contínua mesmo que nenhuma esteja atualmente listada no catálogo CISA KEV, mantendo a taxa de exploração ativa abaixo da média geral do catálogo. A ausência de PoCs públicas e de novas vulnerabilidades nos últimos 90 dias reduz a pressão imediata de remediação, mas não elimina o risco estrutural. O tipo de falha mais recorrente é CWE-98 (Remote File Inclusion), que historicamente permite execução de código arbitrário quando explorada com sucesso e exige controles rigorosos sobre inclusão de arquivos em ambientes PHP. A CVE mais perigosa no momento, CVE-2025-60226, apresenta EPSS de 0,0053, indicando baixa probabilidade de exploração ativa no curto prazo, mas deve ser acompanhada dado o padrão de falhas do vendor.

CVE-2025-26592HIGHWordPress Lab Theme <= 1.0.0 - Local File Inclusion VulnerabilityEPSS 0.8%CVE-2025-50003HIGHWordPress Amuli theme <= 2.3.0 - Local File Inclusion vulnerabilityEPSS 0.6%CVE-2025-60226CRITICALWordPress White Rabbit theme <= 1.5.2 - PHP Object Injection vulnerabilityEPSS 0.6%CVE-2026-65579CRITICALWordPress Agricola theme <= 1.21.0 - PHP Object Injection vulnerabilityEPSS 0.6%CVE-2026-65571CRITICALWordPress 69 Clothing theme <= 1.2.11.1 - PHP Object Injection vulnerabilityEPSS 0.6%CVE-2026-65581CRITICALWordPress AI ANN theme <= 1.29.0 - PHP Object Injection vulnerabilityEPSS 0.6%CVE-2026-57738CRITICALWordPress 777 theme <= 1.13.0 - PHP Object Injection vulnerabilityEPSS 0.6%CVE-2026-65572CRITICALWordPress A.Williams theme <= 1.3.1 - PHP Object Injection vulnerabilityEPSS 0.6%CVE-2026-28119HIGHWordPress Nirvana theme <= 2.6 - Local File Inclusion vulnerabilityEPSS 0.6%CVE-2026-28024HIGHWordPress Helion theme <= 1.1.12 - Local File Inclusion vulnerabilityEPSS 0.6%CVE-2026-28079HIGHWordPress Conquerors theme <= 1.2.13 - Local File Inclusion vulnerabilityEPSS 0.6%CVE-2026-28118HIGHWordPress Welldone theme <= 2.4 - Local File Inclusion vulnerabilityEPSS 0.6%CVE-2026-27326HIGHWordPress AC Services | HVAC, Air Conditioning & Heating Company WordPress Theme theme <= 1.2.5 - Local File Inclusion vulnerabilityEPSS 0.6%CVE-2026-28117HIGHWordPress smart SEO theme <= 2.9 - Local File Inclusion vulnerabilityEPSS 0.6%CVE-2026-28129HIGHWordPress Little Birdies theme <= 1.3.16 - Local File Inclusion vulnerabilityEPSS 0.6%CVE-2025-53435HIGHWordPress Plan My Day theme <= 1.1.13 - Local File Inclusion vulnerabilityEPSS 0.5%CVE-2025-53441HIGHWordPress Greeny theme <= 2.6 - Local File Inclusion vulnerabilityEPSS 0.5%CVE-2025-58942HIGHWordPress Dwell theme <= 1.7.0 - Local File Inclusion vulnerabilityEPSS 0.5%CVE-2025-53442HIGHWordPress Rentic theme <= 1.1 - Local File Inclusion vulnerabilityEPSS 0.5%CVE-2025-58927HIGHWordPress Stallion theme <= 1.17 - Local File Inclusion vulnerabilityEPSS 0.5%