VYPR
Vendor

Wellchoose

Products
5
CVEs
16
Across products
19
Status
Private

Products

5

Recent CVEs

16
  • CVE-2026-3826CriMar 11, 2026
    risk 0.64cvss 9.8epss 0.01

    IFTOP developed by WellChoose has a Local File Inclusion vulnerability, allowing unauthenticated remote attackers to execute arbitrary code on the server.

  • CVE-2025-8913CriAug 13, 2025
    risk 0.64cvss 9.8epss 0.01

    Organization Portal System developed by WellChoose has a Local File Inclusion vulnerability, allowing unauthenticated remote attackers to execute arbitrary code on the server.

  • CVE-2026-1428HigJan 26, 2026
    risk 0.57cvss 8.8epss 0.01

    Single Sign-On Portal System developed by WellChoose has a OS Command Injection vulnerability, allowing authenticated remote attackers to inject arbitrary OS commands and execute them on the server.

  • CVE-2026-1427HigJan 26, 2026
    risk 0.57cvss 8.8epss 0.01

    Single Sign-On Portal System developed by WellChoose has a OS Command Injection vulnerability, allowing authenticated remote attackers to inject arbitrary OS commands and execute them on the server.

  • CVE-2025-7619HigJul 14, 2025
    risk 0.57cvss 8.8epss 0.01

    BatchSignCS, a background Windows application developed by WellChoose, has an Arbitrary File Write vulnerability. If a user visits a malicious website while the application is running, remote attackers can write arbitrary files to any path and potentially lead to arbitrary code…

  • CVE-2024-10202HigOct 21, 2024
    risk 0.57cvss 8.8epss 0.01

    Administrative Management System from Wellchoose has an OS Command Injection vulnerability, allowing remote attackers with regular privileges to inject and execute arbitrary OS commands.

  • CVE-2024-10201HigOct 21, 2024
    risk 0.57cvss 8.8epss 0.01

    Administrative Management System from Wellchoose does not properly validate uploaded file types, allowing remote attackers with regular privileges to upload and execute webshells.

  • CVE-2025-8912HigAug 13, 2025
    risk 0.49cvss 7.5epss 0.01

    Organization Portal System developed by WellChoose has an Arbitrary File Reading vulnerability, allowing unauthenticated remote attackers to exploit Absolute Path Traversal to download arbitrary system files.

  • CVE-2024-10200HigOct 21, 2024
    risk 0.49cvss 7.5epss 0.01

    Administrative Management System from Wellchoose has a Path Traversal vulnerability, allowing unauthenticated remote attackers to exploit this vulnerability to download arbitrary files on the server.

  • CVE-2025-8914MedAug 13, 2025
    risk 0.42cvss 6.5epss 0.00

    Organization Portal System developed by WellChoose has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read database contents.

  • CVE-2025-8909MedAug 13, 2025
    risk 0.42cvss 6.5epss 0.01

    Organization Portal System developed by WellChoose has an Arbitrary File Reading vulnerability, allowing remote attackers with regular privileges to exploit Absolute Path Traversal to download arbitrary system files.

  • CVE-2026-3825MedMar 11, 2026
    risk 0.40cvss 6.1epss 0.00

    IFTOP developed by WellChoose has a Reflected Cross-site Scripting vulnerability, allowing authenticated remote attackers to execute arbitrary JavaScript codes in user's browser through phishing attacks.

  • CVE-2026-3824MedMar 11, 2026
    risk 0.40cvss 6.1epss 0.00

    IFTOP developed by WellChoose has an Open redirect vulnerability, allowing authenticated remote attackers to craft a URL that tricks users into visiting malicious website.

  • CVE-2025-8911MedAug 13, 2025
    risk 0.40cvss 6.1epss 0.00

    Organization Portal System developed by WellChoose has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaScript codes in user's browser through phishing attacks.

  • CVE-2025-8910MedAug 13, 2025
    risk 0.40cvss 6.1epss 0.00

    Organization Portal System developed by WellChoose has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaScript codes in user's browser through phishing attacks.

  • CVE-2026-1429MedJan 26, 2026
    risk 0.35cvss 5.4epss 0.00

    Single Sign-On Portal System developed by WellChoose has a Reflected Cross-site Scripting vulnerability, allowing authenticated remote attackers to execute arbitrary JavaScript codes in user's browser through phishing attacks.