Utarit's vulnerability profile centers on a narrow range of financial and payment-processing applications including Soliclub, SoliPay Mobile, and Persolus that serve transaction and membership management. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and recur through serious authorization and credential-management weakness classes—user-controlled authorization keys, hard-coded credentials, and SQL injection—that directly compromise authentication and data access in payment-sensitive contexts. Defenders should treat this vendor's disclosures as high-priority for any deployment handling financial transactions; live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Utarit over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-7358CRITICAL Use of Hard-coded Credentials vulnerability in Utarit Informatics Services Inc. SoliClub allows Authentication Abuse.
This issue affects SoliClub: before 5.3.7. | Dec 18, 2025 | 9.8 | 34 | NO | NO |
CVE-2023-5155CRITICAL Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Utarit Information Technologies SoliPay Mobile App allows SQL Injection.
This | Feb 15, 2024 | 9.8 | 30 | NO | NO |
CVE-2023-1152CRITICAL Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Utarit Information Technologies Persolus allows SQL Injection. This issue affe | Mar 17, 2023 | 9.8 | 30 | NO | NO |
CVE-2025-1031HIGH Authorization Bypass Through User-Controlled Key vulnerability in Utarit Informatics Services Inc. SoliClub allows Functionality Misuse.
This issue affects SoliClub: from 5.2.4 be | Dec 18, 2025 | 7.5 | 24 | NO | NO |
CVE-2025-1030HIGH Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Utarit Informatics Services Inc. SoliClub allows Query System for Information.
This issue affect | Dec 18, 2025 | 7.5 | 24 | NO | NO |
CVE-2025-1029HIGH Use of Hard-coded Credentials vulnerability in Utarit Information Services Inc. SoliClub allows Read Sensitive Constants Within an Executable.
This issue affects SoliClub: from 5. | Dec 18, 2025 | 7.5 | 24 | NO | NO |
CVE-2023-6255HIGH Use of Hard-coded Credentials vulnerability in Utarit Information Technologies SoliPay Mobile App allows Read Sensitive Strings Within an Executable.
This issue affects SoliPay Mo | Feb 15, 2024 | 7.5 | 24 | NO | NO |
CVE-2024-3305HIGH Authorization Bypass Through User-Controlled Key, Missing Authorization vulnerability in Utarit Information SoliClub allows Retrieve Embedded Sensitive Data.
This issue affects S | Sep 12, 2024 | 7.5 | 22 | NO | NO |
CVE-2023-4993HIGH Incorrect Use of Privileged APIs vulnerability in Utarit Information Technologies SoliPay Mobile App allows Collect Data as Provided by Users.
This issue affects SoliPay Mobile Ap | Feb 15, 2024 | 7.5 | 22 | NO | NO |
CVE-2024-3306HIGH Authorization Bypass Through User-Controlled Key vulnerability in Utarit Information SoliClub allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue a | Sep 12, 2024 | 7.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Utarit.
Media articles that mention a CVE ID that affects a product developed by Utarit — matched by CVE ID, not by vendor name.