Webitr
Vendor:
First CVE: Sep 9, 2024 · Active for 1 year
11
Total CVEs
More Total CVEs than 89% of tracked products
5.5
Avg CVEs / Year
Higher CVE frequency than 89% of tracked products
7.1
Avg CVSS
Higher Avg CVSS than 42% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Webitr over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 9, 2024
22 months ago
Most Recent CVE
Nov 28, 2025
240 days ago
CVE Severity & Scoring
Webitr11 CVEs
73%
18%
9%
All CVEs352,713 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network11 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low11 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None10 (90.9%)
Unknown0 (0.0%)
Required1 (9.1%)
Privileges Required
Low8 (72.7%)
High0 (0.0%)
None3 (27.3%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-9254CRITICAL WebITR developed by Uniong has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to log into the system as arbitrary users by exploiting a specific | Aug 22, 2025 | 9.8 | 32 | NO | NO |
CVE-2025-13768HIGH WebITR developed by Uniong has an Authentication Bypass vulnerability, allowing authenticated remote attackers to log into the system as any user by modifying a specific parameter. | Nov 28, 2025 | 8.8 | 29 | NO | NO |
CVE-2025-9255HIGH WebITR developed by Uniong has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read database contents. | Aug 22, 2025 | 7.5 | 25 | NO | NO |
CVE-2025-13771MEDIUM WebITR developed by Uniong has an Arbitrary File Read vulnerability, allowing authenticated remote attackers to exploit Relative Path Traversal to download arbitrary system files. | Nov 28, 2025 | 6.5 | 23 | NO | NO |
CVE-2025-13770MEDIUM WebITR developed by Uniong has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read database contents. | Nov 28, 2025 | 6.5 | 23 | NO | NO |
CVE-2025-13769MEDIUM WebITR developed by Uniong has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read database contents. | Nov 28, 2025 | 6.5 | 22 | NO | NO |
CVE-2025-9259MEDIUM WebITR developed by Uniong has an Arbitrary File Reading vulnerability, allowing remote attackers with regular privileges to exploit Absolute Path Traversal to download arbitrary s | Aug 22, 2025 | 6.5 | 22 | NO | NO |
CVE-2025-9258MEDIUM WebITR developed by Uniong has an Arbitrary File Reading vulnerability, allowing remote attackers with regular privileges to exploit Absolute Path Traversal to download arbitrary s | Aug 22, 2025 | 6.5 | 22 | NO | NO |
CVE-2025-9257MEDIUM WebITR developed by Uniong has an Arbitrary File Reading vulnerability, allowing remote attackers with regular privileges to exploit Absolute Path Traversal to download arbitrary s | Aug 22, 2025 | 6.5 | 22 | NO | NO |
CVE-2025-9256MEDIUM WebITR developed by Uniong has an Arbitrary File Reading vulnerability, allowing remote attackers with regular privileges to exploit Absolute Path Traversal to download arbitrary s | Aug 22, 2025 | 6.5 | 22 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (11 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (11 CVEs).
Media Mentions
Signals from CVEs in this product scope (11 CVEs).
Top CNAs Publishing CVEs For Webitr
Top CWEs
Versions
No cataloged versions.