Vulnerabilidades em axiomthemes

98 resultados
Análise Vexday

O portfólio de vulnerabilidades da AxiomThemes reúne 85 CVEs catalogadas, das quais 7 são classificadas como críticas — um volume que merece atenção contínua mesmo que nenhuma esteja atualmente listada no catálogo CISA KEV, mantendo a taxa de exploração ativa abaixo da média geral do catálogo. A ausência de PoCs públicas e de novas vulnerabilidades nos últimos 90 dias reduz a pressão imediata de remediação, mas não elimina o risco estrutural. O tipo de falha mais recorrente é CWE-98 (Remote File Inclusion), que historicamente permite execução de código arbitrário quando explorada com sucesso e exige controles rigorosos sobre inclusão de arquivos em ambientes PHP. A CVE mais perigosa no momento, CVE-2025-60226, apresenta EPSS de 0,0053, indicando baixa probabilidade de exploração ativa no curto prazo, mas deve ser acompanhada dado o padrão de falhas do vendor.

CVE-2025-58923HIGHWordPress Critique theme <= 1.17 - Local File Inclusion vulnerabilityEPSS 0.5%CVE-2025-58943HIGHWordPress Agricola theme <= 1.1.0 - Local File Inclusion vulnerabilityEPSS 0.5%CVE-2025-53453HIGHWordPress Hygia theme <= 1.16 - Local File Inclusion vulnerabilityEPSS 0.5%CVE-2025-58927HIGHWordPress Stallion theme <= 1.17 - Local File Inclusion vulnerabilityEPSS 0.5%CVE-2025-53441HIGHWordPress Greeny theme <= 2.6 - Local File Inclusion vulnerabilityEPSS 0.5%CVE-2025-69409HIGHWordPress PJ | Life & Business Coaching theme <= 3.0.0 - Local File Inclusion vulnerabilityEPSS 0.5%CVE-2026-22363HIGHWordPress Rhodos theme <= 1.3.3 - Local File Inclusion vulnerabilityEPSS 0.5%CVE-2026-22361HIGHWordPress A-Mart theme <= 1.0.2 - Local File Inclusion vulnerabilityEPSS 0.5%CVE-2026-22366HIGHWordPress Jude theme <= 1.3.0 - Local File Inclusion vulnerabilityEPSS 0.5%CVE-2026-22500CRITICALWordPress m2 | Construction and Tools Store theme <= 1.1.2 - PHP Object Injection vulnerabilityEPSS 0.5%CVE-2026-22501CRITICALWordPress Mounthood theme <= 1.3.2 - PHP Object Injection vulnerabilityEPSS 0.5%CVE-2025-49434CRITICALWordPress Cars4Rent Theme <= 1.4.2 - PHP Object Injection VulnerabilityEPSS 0.5%CVE-2025-60063HIGHWordPress Rosalinda theme <= 1.2.3 - Local File Inclusion vulnerabilityEPSS 0.5%CVE-2025-60064HIGHWordPress Renewal theme <= 1.2.2 - Local File Inclusion vulnerabilityEPSS 0.5%CVE-2025-60046HIGHWordPress HeartStar theme <= 1.0.14 - Local File Inclusion vulnerabilityEPSS 0.5%CVE-2025-60060HIGHWordPress Pubzinne theme <= 1.0.12 - Local File Inclusion vulnerabilityEPSS 0.5%CVE-2025-60061HIGHWordPress Kicker theme <= 2.2.0 - Local File Inclusion vulnerabilityEPSS 0.5%CVE-2025-58929HIGHWordPress Pantry theme <= 1.4 - Local File Inclusion vulnerabilityEPSS 0.5%CVE-2025-58708HIGHWordPress 777 theme <= 1.3 - Local File Inclusion vulnerabilityEPSS 0.5%CVE-2025-60050HIGHWordPress Panda theme <= 1.21 - Local File Inclusion vulnerabilityEPSS 0.5%