Wellchoose develops a focused portfolio of web-facing administrative and authentication systems, including portal and single sign-on products, that handle identity and organizational workflows. Vulnerabilities affecting the vendor skew toward serious outcomes and recur through input-handling and file-inclusion weaknesses including cross-site scripting, path traversal, OS command injection, and PHP remote file inclusion—flaws endemic to web application layers where user input reaches system commands and file operations. Defenders should prioritize this vendor's advisories for internet-reachable portal and SSO deployments, as these product categories represent high-value authentication targets; live severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wellchoose over time
Signals from CVEs in this vendor scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-8913CRITICAL Organization Portal System developed by WellChoose has a Local File Inclusion vulnerability, allowing unauthenticated remote attackers to execute arbitrary code on the server. | Aug 13, 2025 | 9.8 | 32 | NO | NO |
CVE-2026-3826CRITICAL IFTOP developed by WellChoose has a Local File Inclusion vulnerability, allowing unauthenticated remote attackers to execute arbitrary code on the server. | Mar 11, 2026 | 9.8 | 31 | NO | NO |
CVE-2026-1428HIGH Single Sign-On Portal System developed by WellChoose has a OS Command Injection vulnerability, allowing authenticated remote attackers to inject arbitrary OS commands and execute t | Jan 26, 2026 | 8.8 | 30 | NO | NO |
CVE-2026-1427HIGH Single Sign-On Portal System developed by WellChoose has a OS Command Injection vulnerability, allowing authenticated remote attackers to inject arbitrary OS commands and execute t | Jan 26, 2026 | 8.8 | 27 | NO | NO |
CVE-2024-10202HIGH Administrative Management System from Wellchoose has an OS Command Injection vulnerability, allowing remote attackers with regular privileges to inject and execute arbitrary OS com | Oct 21, 2024 | 8.8 | 26 | NO | NO |
CVE-2025-8914HIGH Organization Portal System developed by WellChoose has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read database co | Aug 13, 2025 | 7.5 | 25 | NO | NO |
CVE-2025-8912HIGH Organization Portal System developed by WellChoose has an Arbitrary File Reading vulnerability, allowing unauthenticated remote attackers to exploit Absolute Path Traversal to down | Aug 13, 2025 | 7.5 | 25 | NO | NO |
CVE-2024-10201HIGH Administrative Management System from Wellchoose does not properly validate uploaded file types, allowing remote attackers with regular privileges to upload and execute webshells. | Oct 21, 2024 | 8.8 | 25 | NO | NO |
CVE-2025-8911MEDIUM Organization Portal System developed by WellChoose has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaScript cod | Aug 13, 2025 | 6.1 | 22 | NO | NO |
CVE-2025-8910MEDIUM Organization Portal System developed by WellChoose has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaScript cod | Aug 13, 2025 | 6.1 | 22 | NO | NO |
Signals from CVEs in this vendor scope (15 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wellchoose.
Media articles that mention a CVE ID that affects a product developed by Wellchoose — matched by CVE ID, not by vendor name.