Products: 7
    Vulnerabilities: 11
    Known Exploited: 0
    2
    Critical Level Threats
    4
    High Level Threats
    5
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2024-28735

    Unit4 Financials by Coda versions prior to 2023Q4 suffer from an incorrect access control authorization bypass vulnerability which allows an authenticated user to modify the password of any user of the application via a crafted request.

    Last Modified: Jun 17, 2025
    Published: Mar 20, 2024

    CVE-2024-28734

    Cross Site Scripting vulnerability in Unit4 Financials by Coda prior to 2023Q4 allows a remote attacker to run arbitrary code via a crafted GET request using the cols parameter.

    Last Modified: Apr 15, 2026
    Published: Mar 19, 2024

    CVE-2022-34001

    Unit4 ERP through 7.9 allows XXE via ExecuteServerProcessAsynchronously.

    Last Modified: Nov 21, 2024
    Published: Jul 19, 2022

    CVE-2022-27434

    UNIT4 TETA Mobile Edition (ME) before 29.5.HF17 was discovered to contain a SQL injection vulnerability via the ProfileName parameter in the errorReporting page.

    Last Modified: Nov 21, 2024
    Published: Jul 17, 2022

    CVE-2021-36233

    The function AdminGetFirstFileContentByFilePath in MIK.starlight 7.9.5.24363 allows (by design) an authenticated attacker to read arbitrary files from the filesystem by specifying the file path.

    Last Modified: Nov 21, 2024
    Published: Aug 31, 2021
    Items Per Page
    Unit4 Vulnerabilities & Security CVEs | CVE-DB