Edetw maintains a focused product line centered on the U-Office Force office and productivity suite, which sits among the more prominent vendors in the vulnerability landscape despite a narrow portfolio. Vulnerabilities affecting this vendor skew toward serious outcomes, with a meaningful share reaching critical severity, and recur through classic web-application and data-handling weakness classes including cross-site scripting, path traversal, SQL injection, unsafe file uploads, and untrusted deserialization that are characteristic of legacy or rapidly evolved business software. Defenders should prioritize patches for this vendor's office suite and audit instances for input-validation and access-control weaknesses; live severity and exploitation details are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Edetw over time
Signals from CVEs in this vendor scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-3422CRITICAL U-Office Force developed by e-Excellence has a Insecure Deserialization vulnerability, allowing unauthenticated remote attackers to execute arbitrary code on the server by sending | Mar 2, 2026 | 9.8 | 34 | NO | NO |
CVE-2025-12865HIGH U-Office Force developed by e-Excellence has a SQL Injection vulnerability, allowing authenticated remote attacker to inject arbitrary SQL commands to read, modify, and delete data | Nov 10, 2025 | 8.8 | 30 | NO | NO |
CVE-2025-12864HIGH U-Office Force developed by e-Excellence has a SQL Injection vulnerability, allowing authenticated remote attacker to inject arbitrary SQL commands to read, modify, and delete data | Nov 10, 2025 | 8.8 | 30 | NO | NO |
CVE-2025-2395CRITICAL The U-Office Force from e-Excellence has an Improper Authentication vulnerability, allowing unauthenticated remote attackers to use a particular API and alter cookies to log in as | Mar 17, 2025 | 9.8 | 28 | NO | NO |
CVE-2023-32757CRITICAL
e-Excellence U-Office Force file uploading function does not restrict upload of file with dangerous type. An unauthenticated remote attacker without logging the service can exploi | Aug 25, 2023 | 9.8 | 28 | NO | NO |
CVE-2025-2396HIGH The U-Office Force from e-Excellence has an Arbitrary File Upload vulnerability, allowing remote attackers with regular privileges to upload and execute web shell backdoors, thereb | Mar 17, 2025 | 8.8 | 25 | NO | NO |
CVE-2023-32756HIGH
e-Excellence U-Office Force has a path traversal vulnerability within its file uploading and downloading functions. An unauthenticated remote attacker can exploit this vulnerabili | Aug 25, 2023 | 7.5 | 23 | NO | NO |
CVE-2022-39023MEDIUM U-Office Force Download function has a path traversal vulnerability. A remote attacker with general user privilege can exploit this vulnerability to download arbitrary system file. | Oct 31, 2022 | 6.5 | 23 | NO | NO |
CVE-2022-39022MEDIUM U-Office Force Download function has a path traversal vulnerability. A remote attacker with general user privilege can exploit this vulnerability to download arbitrary system file. | Oct 31, 2022 | 6.5 | 23 | NO | NO |
CVE-2022-39025MEDIUM U-Office Force PrintMessage function has insufficient filtering for special characters. An unauthenticated remote attacker can exploit this vulnerability to inject JavaScript and p | Oct 31, 2022 | 6.1 | 22 | NO | NO |
Signals from CVEs in this vendor scope (15 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Edetw.
Media articles that mention a CVE ID that affects a product developed by Edetw — matched by CVE ID, not by vendor name.