Unigroup operates an electronic archives system that handles sensitive document management and storage, areas where access control and input validation carry particular weight. The observed vulnerability pattern centers on path traversal, improper access controls, injection flaws including SQL injection, and unsafe file-upload handling—weaknesses characteristic of web-facing systems that parse user input and manage file repositories. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Unigroup over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-2684CRITICAL A vulnerability was determined in Tsinghua Unigroup Electronic Archives System up to 3.2.210802(62532). The impacted element is an unknown function of the file /Archive/ErecordMana | Feb 19, 2026 | 9.8 | 31 | NO | NO |
CVE-2026-2682CRITICAL A vulnerability has been found in Tsinghua Unigroup Electronic Archives System up to 3.2.210802(62532). Impacted is an unknown function of the file /mine/PublicReport/prinReport.ht | Feb 18, 2026 | 9.8 | 30 | NO | NO |
CVE-2026-2672MEDIUM A security flaw has been discovered in Tsinghua Unigroup Electronic Archives System 3.2.210802(62532). Affected by this vulnerability is the function Download of the file /Search/S | Feb 18, 2026 | 5.3 | 20 | NO | NO |
CVE-2026-2683MEDIUM A vulnerability was found in Tsinghua Unigroup Electronic Archives System 3.2.210802(62532). The affected element is an unknown function of the file /Using/Subject/downLoad.html. P | Feb 18, 2026 | 4.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Unigroup.
Media articles that mention a CVE ID that affects a product developed by Unigroup — matched by CVE ID, not by vendor name.