Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Unit4

First CVE: Feb 25, 2015Active for: 11 yearsTotal CVEs: 10
30.6
VTI Score
Low

Unit4 is an enterprise resource planning and human capital management vendor whose vulnerability footprint spans financial, payroll, and workforce management platforms, many of which handle sensitive operational and personal data. The recurring exposure centers on authentication, access control, and input-handling weaknesses—including deserialization flaws, credential validation issues, and cross-site scripting—that are characteristic of complex web-facing business applications, and vulnerabilities affecting the vendor skew toward serious outcomes. Defenders should prioritize patches for internet-reachable instances and review access controls around financial and HR data; current severity and exploitation metrics are shown alongside this summary.

FAUCET AI Generated
10
Total CVEs
More Total CVEs than 92% of tracked vendors
0.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 3% of tracked vendors
7.6
Avg CVSS Score
Higher Avg CVSS Score than 72% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Unit4 over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 25, 2015
11 years ago
Most Recent CVE
Mar 20, 2024
856 days ago

Products(6 total)

Top CVEs

Signals from CVEs in this vendor scope (10 CVEs).

10 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-27434CRITICAL
UNIT4 TETA Mobile Edition (ME) before 29.5.HF17 was discovered to contain a SQL injection vulnerability via the ProfileName parameter in the errorReporting page.
Jul 18, 20229.832NONO
CVE-2021-36232HIGH
Improper Authorization in multiple functions in MIK.starlight 7.9.5.24363 allows an authenticated attacker to escalate privileges.
Aug 31, 20218.828NONO
CVE-2021-36231HIGH
Deserialization of untrusted data in multiple functions in MIK.starlight 7.9.5.24363 allows authenticated remote attackers to execute operating system commands by crafting serializ
Aug 31, 20218.828NONO
CVE-2015-1174CRITICAL
Session fixation vulnerability in Unit4 Polska TETA Web (formerly TETA Galactica) 22.62.3.4 and earlier allows remote attackers to hijack web sessions via a session id.
Aug 2, 20179.828NONO
CVE-2024-28735HIGH
Unit4 Financials by Coda versions prior to 2023Q4 suffer from an incorrect access control authorization bypass vulnerability which allows an authenticated user to modify the passwo
Mar 20, 20248.125NONO
CVE-2022-34001MEDIUM
Unit4 ERP through 7.9 allows XXE via ExecuteServerProcessAsynchronously.
Jul 19, 20226.523NONO
CVE-2021-36233MEDIUM
The function AdminGetFirstFileContentByFilePath in MIK.starlight 7.9.5.24363 allows (by design) an authenticated attacker to read arbitrary files from the filesystem by specifying
Aug 31, 20216.522NONO
CVE-2021-36234MEDIUM
Use of a hard-coded cryptographic key in MIK.starlight 7.9.5.24363 allows local users to decrypt credentials via unspecified vectors.
Aug 31, 20215.520NONO
CVE-2015-1173HIGH
Unit4 Polska TETA Web (formerly TETA Galactica) 22.62.3.4 does not properly restrict access to the (1) Design Mode and (2) Debug Logger mode modules, which allows remote attackers
Sep 16, 20157.520NONO
CVE-2015-2082MEDIUM
Cross-site scripting (XSS) vulnerability in Login.aspx in UNIT4 Prosoft HRMS before 8.14.330.43 allows remote attackers to inject arbitrary web script or HTML via the txtUserID par
Feb 25, 20154.314NONO
View all 10 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products10 CVEs
40%
40%
20%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (10.0%)
Network7 (70.0%)
Unknown2 (20.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (80.0%)
High0 (0.0%)
Unknown2 (20.0%)
User Interaction
None8 (80.0%)
Unknown2 (20.0%)
Required0 (0.0%)
Privileges Required
Low6 (60.0%)
High0 (0.0%)
None2 (20.0%)
Unknown2 (20.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (10 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Unit4.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Unit4 — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Unit4's Products

View all 1 CNAs →

Top CWEs