VYPR
Vendor

Uniguest

Products
1
CVEs
7
Across products
7
Status
Private

Products

1

Recent CVEs

7
  • CVE-2024-50707CriMar 4, 2025
    risk 0.65cvss 10.0epss 0.01

    Unauthenticated remote code execution vulnerability in Uniguest Tripleplay before 24.2.1 allows remote attackers to execute arbitrary code via the X-Forwarded-For header in an HTTP GET request.

  • CVE-2024-50704CriMar 4, 2025
    risk 0.65cvss 10.0epss 0.01

    Unauthenticated remote code execution vulnerability in Uniguest Tripleplay before 24.2.1 allows remote attackers to execute arbitrary code via a specially crafted HTTP POST request.

  • CVE-2024-50706CriMar 4, 2025
    risk 0.64cvss 9.8epss 0.01

    Unauthenticated SQL injection vulnerability in Uniguest Tripleplay version 23.1+ allows remote attackers to execute arbitrary SQL queries on the backend database.

  • CVE-2023-25760HigApr 19, 2023
    risk 0.57cvss 8.8epss 0.01

    Incorrect Access Control in Tripleplay Platform releases prior to Caveman 3.4.0 allows authenticated user to modify other users passwords via a crafted request payload

  • CVE-2024-50705HigMar 4, 2025
    risk 0.46cvss 7.1epss 0.00

    Unauthenticated reflected cross-site scripting (XSS) vulnerability in Uniguest Tripleplay before 24.2.1 allows remote attackers to execute arbitrary scripts via the page parameter.

  • CVE-2023-26599MedApr 19, 2023
    risk 0.40cvss 6.1epss 0.00

    XSS vulnerability in TripleSign in Tripleplay Platform releases prior to Caveman 3.4.0 allows attackers to inject client-side code to run as an authenticated user via a crafted link.

  • CVE-2023-25759MedApr 19, 2023
    risk 0.35cvss 5.4epss 0.01

    OS Command Injection in TripleData Reporting Engine in Tripleplay Platform releases prior to Caveman 3.4.0 allows authenticated users to run unprivileged OS level commands via a crafted request payload.