Uipress develops a WordPress plugin (Uipress Lite) that provides user interface customization and management functionality. The observed vulnerability exposure centers on SQL injection weaknesses in command construction, a pattern typical of application-layer plugins handling user input and database queries. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Uipress over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-38788HIGH Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Bởi Admin 2020 UiPress lite allows SQL Injection.This issue affects UiPress li | Jul 22, 2024 | 7.2 | 22 | NO | NO |
CVE-2026-27091MEDIUM Missing Authorization vulnerability in UiPress UiPress lite uipress-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects UiPress lite: fr | Mar 19, 2026 | 6.3 | 21 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Uipress.
Media articles that mention a CVE ID that affects a product developed by Uipress — matched by CVE ID, not by vendor name.