Uniong develops web-based IT infrastructure and resource management applications, with its WebITR product serving as the focus of its vulnerability footprint. The vendor's disclosures center on application-layer weaknesses including path traversal, SQL injection, authorization bypass, and missing authentication controls on critical functions—flaws characteristic of web applications with complex permission models and user-supplied input handling. Current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Uniong over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-9254CRITICAL WebITR developed by Uniong has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to log into the system as arbitrary users by exploiting a specific | Aug 22, 2025 | 9.8 | 32 | NO | NO |
CVE-2025-13768HIGH WebITR developed by Uniong has an Authentication Bypass vulnerability, allowing authenticated remote attackers to log into the system as any user by modifying a specific parameter. | Nov 28, 2025 | 8.8 | 29 | NO | NO |
CVE-2025-9255HIGH WebITR developed by Uniong has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read database contents. | Aug 22, 2025 | 7.5 | 25 | NO | NO |
CVE-2025-13771MEDIUM WebITR developed by Uniong has an Arbitrary File Read vulnerability, allowing authenticated remote attackers to exploit Relative Path Traversal to download arbitrary system files. | Nov 28, 2025 | 6.5 | 23 | NO | NO |
CVE-2025-13770MEDIUM WebITR developed by Uniong has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read database contents. | Nov 28, 2025 | 6.5 | 23 | NO | NO |
CVE-2025-13769MEDIUM WebITR developed by Uniong has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read database contents. | Nov 28, 2025 | 6.5 | 22 | NO | NO |
CVE-2025-9259MEDIUM WebITR developed by Uniong has an Arbitrary File Reading vulnerability, allowing remote attackers with regular privileges to exploit Absolute Path Traversal to download arbitrary s | Aug 22, 2025 | 6.5 | 22 | NO | NO |
CVE-2025-9258MEDIUM WebITR developed by Uniong has an Arbitrary File Reading vulnerability, allowing remote attackers with regular privileges to exploit Absolute Path Traversal to download arbitrary s | Aug 22, 2025 | 6.5 | 22 | NO | NO |
CVE-2025-9257MEDIUM WebITR developed by Uniong has an Arbitrary File Reading vulnerability, allowing remote attackers with regular privileges to exploit Absolute Path Traversal to download arbitrary s | Aug 22, 2025 | 6.5 | 22 | NO | NO |
CVE-2025-9256MEDIUM WebITR developed by Uniong has an Arbitrary File Reading vulnerability, allowing remote attackers with regular privileges to exploit Absolute Path Traversal to download arbitrary s | Aug 22, 2025 | 6.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Uniong.
Media articles that mention a CVE ID that affects a product developed by Uniong — matched by CVE ID, not by vendor name.