Loftware develops label-management and enterprise-printing software, with its Spectrum product serving as a core component for organizations managing print operations and regulatory compliance across supply chains. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and recur through structural weaknesses in server-request handling, data deserialization, access control, and sensitive-information disclosure that are characteristic of server-side application platforms. Defenders should prioritize updates to internet-exposed Spectrum instances and review access controls around print infrastructure; current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Loftware over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-37227CRITICAL Loftware Spectrum before 4.6 HF13 Deserializes Untrusted Data. | Sep 10, 2024 | 9.8 | 30 | NO | NO |
CVE-2023-37234CRITICAL Loftware Spectrum through 4.6 has unprotected JMX Registry. | Sep 10, 2024 | 9.8 | 28 | NO | NO |
CVE-2023-37231CRITICAL Loftware Spectrum before 4.6 HF14 uses a Hard-coded Password. | Sep 10, 2024 | 9.8 | 27 | NO | NO |
CVE-2023-37226CRITICAL Loftware Spectrum before 4.6 HF14 has Missing Authentication for a Critical Function. | Sep 10, 2024 | 9.8 | 27 | NO | NO |
CVE-2023-37230HIGH Loftware Spectrum (testDeviceConnection) before 5.1 allows SSRF. | Sep 10, 2024 | 8.8 | 25 | NO | NO |
CVE-2023-37229HIGH Loftware Spectrum before 5.1 allows SSRF. | Sep 10, 2024 | 8.8 | 25 | NO | NO |
CVE-2023-37233HIGH Loftware Spectrum before 4.6 HF14 allows authenticated XXE attacks. | Sep 10, 2024 | 8.8 | 24 | NO | NO |
CVE-2023-37232HIGH Loftware Spectrum through 4.6 exposes Sensitive Information (Logs) to an Unauthorized Actor. | Sep 10, 2024 | 7.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Loftware.
Media articles that mention a CVE ID that affects a product developed by Loftware — matched by CVE ID, not by vendor name.