Unit4 is an enterprise resource planning and human capital management vendor whose vulnerability footprint spans financial, payroll, and workforce management platforms, many of which handle sensitive operational and personal data. The recurring exposure centers on authentication, access control, and input-handling weaknesses—including deserialization flaws, credential validation issues, and cross-site scripting—that are characteristic of complex web-facing business applications, and vulnerabilities affecting the vendor skew toward serious outcomes. Defenders should prioritize patches for internet-reachable instances and review access controls around financial and HR data; current severity and exploitation metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Unit4 over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-27434CRITICAL UNIT4 TETA Mobile Edition (ME) before 29.5.HF17 was discovered to contain a SQL injection vulnerability via the ProfileName parameter in the errorReporting page. | Jul 18, 2022 | 9.8 | 32 | NO | NO |
CVE-2021-36232HIGH Improper Authorization in multiple functions in MIK.starlight 7.9.5.24363 allows an authenticated attacker to escalate privileges. | Aug 31, 2021 | 8.8 | 28 | NO | NO |
CVE-2021-36231HIGH Deserialization of untrusted data in multiple functions in MIK.starlight 7.9.5.24363 allows authenticated remote attackers to execute operating system commands by crafting serializ | Aug 31, 2021 | 8.8 | 28 | NO | NO |
CVE-2015-1174CRITICAL Session fixation vulnerability in Unit4 Polska TETA Web (formerly TETA Galactica) 22.62.3.4 and earlier allows remote attackers to hijack web sessions via a session id. | Aug 2, 2017 | 9.8 | 28 | NO | NO |
CVE-2024-28735HIGH Unit4 Financials by Coda versions prior to 2023Q4 suffer from an incorrect access control authorization bypass vulnerability which allows an authenticated user to modify the passwo | Mar 20, 2024 | 8.1 | 25 | NO | NO |
CVE-2022-34001MEDIUM Unit4 ERP through 7.9 allows XXE via ExecuteServerProcessAsynchronously. | Jul 19, 2022 | 6.5 | 23 | NO | NO |
CVE-2021-36233MEDIUM The function AdminGetFirstFileContentByFilePath in MIK.starlight 7.9.5.24363 allows (by design) an authenticated attacker to read arbitrary files from the filesystem by specifying | Aug 31, 2021 | 6.5 | 22 | NO | NO |
CVE-2021-36234MEDIUM Use of a hard-coded cryptographic key in MIK.starlight 7.9.5.24363 allows local users to decrypt credentials via unspecified vectors. | Aug 31, 2021 | 5.5 | 20 | NO | NO |
CVE-2015-1173HIGH Unit4 Polska TETA Web (formerly TETA Galactica) 22.62.3.4 does not properly restrict access to the (1) Design Mode and (2) Debug Logger mode modules, which allows remote attackers | Sep 16, 2015 | 7.5 | 20 | NO | NO |
CVE-2015-2082MEDIUM Cross-site scripting (XSS) vulnerability in Login.aspx in UNIT4 Prosoft HRMS before 8.14.330.43 allows remote attackers to inject arbitrary web script or HTML via the txtUserID par | Feb 25, 2015 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Unit4.
Media articles that mention a CVE ID that affects a product developed by Unit4 — matched by CVE ID, not by vendor name.