Uniguest develops property-management and guest-experience software, principally the TriplePlay platform, which serves hospitality operations and sits at the intersection of guest-facing and administrative systems. The vendor's vulnerability exposure centers on web-application input-handling and code-execution weaknesses—including code injection, command injection, SQL injection, cross-site scripting, and cross-site request forgery—that are characteristic of complex web platforms, and skews strongly toward critical-severity outcomes. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Uniguest over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-50704CRITICAL Unauthenticated remote code execution vulnerability in Uniguest Tripleplay before 24.2.1 allows remote attackers to execute arbitrary code via a specially crafted HTTP POST request | Mar 4, 2025 | 10.0 | 28 | NO | NO |
CVE-2024-50707CRITICAL Unauthenticated remote code execution vulnerability in Uniguest Tripleplay before 24.2.1 allows remote attackers to execute arbitrary code via the X-Forwarded-For header in an HTTP | Mar 4, 2025 | 10.0 | 27 | NO | NO |
CVE-2023-25760HIGH Incorrect Access Control in Tripleplay Platform releases prior to Caveman 3.4.0 allows authenticated user to modify other users passwords via a crafted request payload | Apr 19, 2023 | 8.8 | 27 | NO | NO |
CVE-2024-50706CRITICAL Unauthenticated SQL injection vulnerability in Uniguest Tripleplay version 23.1+ allows remote attackers to execute arbitrary SQL queries on the backend database. | Mar 4, 2025 | 9.8 | 26 | NO | NO |
CVE-2023-26599MEDIUM XSS vulnerability in TripleSign in Tripleplay Platform releases prior to Caveman 3.4.0 allows attackers to inject client-side code to run as an authenticated user via a crafted lin | Apr 19, 2023 | 6.1 | 21 | NO | NO |
CVE-2023-25759MEDIUM OS Command Injection in TripleData Reporting Engine in Tripleplay Platform releases prior to Caveman 3.4.0 allows authenticated users to run unprivileged OS level commands via a cr | Apr 19, 2023 | 5.4 | 20 | NO | NO |
CVE-2024-50705HIGH Unauthenticated reflected cross-site scripting (XSS) vulnerability in Uniguest Tripleplay before 24.2.1 allows remote attackers to execute arbitrary scripts via the page parameter. | Mar 4, 2025 | 7.1 | 19 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Uniguest.
Media articles that mention a CVE ID that affects a product developed by Uniguest — matched by CVE ID, not by vendor name.