Sun.Net maintains a small portfolio of enterprise resource planning and web-based management applications, with a vulnerability profile that is disproportionately weighted toward critical-severity outcomes. The exposure concentrates in products such as EHRD CTMS and WMPro and recurs consistently through application-layer input-handling weaknesses, including SQL injection, cross-site scripting, path traversal, OS command injection, and unrestricted file uploads—vulnerability classes that reflect common gaps in server-side input validation and sanitization. These weakness patterns are characteristic of legacy web application architectures and suggest systemic validation deficiencies across the vendor's codebase that warrant sustained attention from defenders deploying these systems. Organizations running Sun.Net applications should prioritize input filtering, least-privilege execution contexts, and network segmentation to contain the blast radius of these predictable flaws. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sun.Net over time
Signals from CVEs in this vendor scope (21 CVEs).
21 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-7489HIGH CTMS developed by Sunnet has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents. | May 2, 2026 | 8.8 | 35 | NO | NO |
CVE-2025-54942CRITICAL A missing authentication for critical function vulnerability in SUNNET Corporate Training Management System before 10.11 allows remote attackers to access deployment functionality | Aug 30, 2025 | 9.8 | 34 | NO | NO |
CVE-2025-15226CRITICAL WMPro developed by Sunnet has a Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary | Dec 29, 2025 | 9.8 | 32 | NO | NO |
CVE-2025-54946CRITICAL A SQL injection vulnerability in SUNNET Corporate Training Management System before 10.11 allows remote attackers to execute arbitrary SQL commands. | Aug 30, 2025 | 9.8 | 32 | NO | NO |
CVE-2025-54945CRITICAL An external control of file name or path vulnerability in SUNNET Corporate Training Management System before 10.11 allows remote attackers to execute arbitrary system commands via | Aug 30, 2025 | 9.8 | 32 | NO | NO |
CVE-2025-54943CRITICAL A missing authorization vulnerability in SUNNET Corporate Training Management System before 10.11 allows remote attackers to perform unauthorized application deployment due to the | Aug 30, 2025 | 9.8 | 31 | NO | NO |
CVE-2019-11062CRITICAL The SUNNET WMPro v5.0 and v5.1 for eLearning system has OS Command Injection via "/teach/course/doajaxfileupload.php". The target server can be exploited without authentication. | Jul 11, 2019 | 9.8 | 31 | NO | NO |
CVE-2026-7490HIGH CTMS and CPAS developed by Sunnet has an Arbitrary File Upload vulnerability, allowing privileged remote attackers to upload and execute web shell backdoors, thereby enabling arbit | May 2, 2026 | 7.2 | 30 | NO | NO |
CVE-2025-54944CRITICAL An unrestricted upload of file with dangerous type vulnerability in SUNNET Corporate Training Management System before 10.11 allows remote attackers to write malicious code in a sp | Aug 30, 2025 | 9.8 | 30 | NO | NO |
CVE-2024-10440CRITICAL The eHDR CTMS from Sunnet has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL command to read, modify, and delete database contents | Oct 28, 2024 | 9.8 | 26 | NO | NO |
Signals from CVEs in this vendor scope (21 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sun.Net.
Media articles that mention a CVE ID that affects a product developed by Sun.Net — matched by CVE ID, not by vendor name.