Soft8soft focuses on web-based 3D visualization and application development through its Verge3D platform, which enables interactive content creation and deployment across browser and mobile environments. The vendor's disclosed vulnerabilities center on input-handling and file-processing weaknesses characteristic of dynamic web platforms, specifically code injection and unrestricted file upload issues that can arise from permissive content-generation workflows. Current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Soft8soft over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-51420HIGH Improper Control of Generation of Code ('Code Injection') vulnerability in Soft8Soft LLC Verge3D Publishing and E-Commerce.This issue affects Verge3D Publishing and E-Commerce: fro | Dec 29, 2023 | 8.8 | 27 | NO | NO |
CVE-2023-51421HIGH Unrestricted Upload of File with Dangerous Type vulnerability in Soft8Soft LLC Verge3D Publishing and E-Commerce.This issue affects Verge3D Publishing and E-Commerce: from n/a thro | Dec 29, 2023 | 8.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Soft8soft.
Media articles that mention a CVE ID that affects a product developed by Soft8soft — matched by CVE ID, not by vendor name.