CVE-2025-49507: Loftocean Cozystay
Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.
Deserialization of Untrusted Data vulnerability in LoftOcean CozyStay cozystay allows Object Injection.This issue affects CozyStay: from n/a through < 1.7.1.
Affected products
- Loftocean Cozystay: up to and including 1.7.1
Published 2025-06-10. Last modified 2026-06-17.