Uatech maintains a narrowly scoped product portfolio centered on the Badaso web application framework, which despite modest volume commands disproportionate attention due to the serious severity profile of its disclosed vulnerabilities. The exposure recurs through application-layer weakness classes including cross-site scripting, unrestricted file uploads, and weak password-recovery mechanisms, reflecting input-validation and access-control challenges common to web development frameworks. Defenders deploying or extending Badaso should prioritize patching for critical-severity issues and conduct strict input-handling and file-upload controls; current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Uatech over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-41705CRITICAL Badaso version 2.6.3 allows an unauthenticated remote attacker to execute arbitrary code remotely on the server. This is possible because the application does not properly validate | Nov 25, 2022 | 9.8 | 32 | NO | NO |
CVE-2025-52353CRITICAL An arbitrary code execution vulnerability in Badaso CMS 2.9.11. The Media Manager allows authenticated users to upload files containing embedded PHP code via the file-upload endpoi | Aug 26, 2025 | 9.8 | 30 | NO | NO |
CVE-2022-41711CRITICAL Badaso version 2.6.0 allows an unauthenticated remote attacker to execute arbitrary code remotely on the server. This is possible because the application does not properly validate | Oct 25, 2022 | 9.8 | 30 | NO | NO |
CVE-2025-15398HIGH A security vulnerability has been detected in Uasoft badaso up to 2.9.7. Affected is the function forgetPassword of the file src/Controllers/BadasoAuthController.php of the compone | Dec 31, 2025 | 8.1 | 26 | NO | NO |
CVE-2023-38970MEDIUM Cross Site Scripting vulnerabiltiy in Badaso v.0.0.1 thru v.2.9.7 allows a remote attacker to execute arbitrary code via a crafted payload to the Name of member parameter in the ad | Aug 30, 2023 | 5.4 | 18 | NO | NO |
CVE-2023-38971MEDIUM Cross Site Scripting vulnerabiltiy in Badaso v.0.0.1 thru v.2.9.7 allows a remote attacker to execute arbitrary code via a crafted payload to the rack number parameter in the add n | Aug 29, 2023 | 5.4 | 18 | NO | NO |
CVE-2023-38973MEDIUM A stored cross-site scripting (XSS) vulnerability in the Add Tag function of Badaso v2.9.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected | Aug 25, 2023 | 5.4 | 18 | NO | NO |
CVE-2023-38969MEDIUM Cross Site Scripting vulnerabiltiy in Badaso v.2.9.7 allows a remote attacker to execute arbitrary code via a crafted payload to the title parameter in the new book and edit book f | Aug 28, 2023 | 5.4 | 17 | NO | NO |
CVE-2023-38974MEDIUM A stored cross-site scripting (XSS) vulnerability in the Edit Category function of Badaso v2.9.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload inj | Aug 25, 2023 | 5.4 | 16 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Uatech.
Media articles that mention a CVE ID that affects a product developed by Uatech — matched by CVE ID, not by vendor name.