Sunnet
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Sunnet product.
RSS Feeds for Sunnet security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Sunnet products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Sunnet Sorted by Most Security Vulnerabilities since 2018
By the Year
In 2026 there have been 2 vulnerabilities in Sunnet with an average score of 8.0 out of ten. Last year, in 2025 Sunnet had 3 security vulnerabilities published. Right now, Sunnet is on track to have less security vulnerabilities in 2026 than it did last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.07.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 2 | 8.00 |
| 2025 | 3 | 7.93 |
| 2024 | 3 | 8.27 |
| 2023 | 3 | 7.83 |
| 2022 | 0 | 0.00 |
| 2021 | 0 | 0.00 |
| 2020 | 0 | 0.00 |
| 2019 | 1 | 9.80 |
It may take a day or so for new Sunnet vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Sunnet Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-7490 | May 02, 2026 |
Sunnet CTMS/CPAS Arbitrary File Upload Remote Code Execution via Web ShellCTMS and CPAS developed by Sunnet has an Arbitrary File Upload vulnerability, allowing privileged remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server. |
|
| CVE-2026-7489 | May 02, 2026 |
SQLi in Sunnet CTMS allows remote DB tamperingCTMS developed by Sunnet has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents. |
|
| CVE-2025-15226 | Dec 29, 2025 |
WMPro developed by Sunnet has a Arbitrary File Upload vulnerabilityWMPro developed by Sunnet has a Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server. |
|
| CVE-2025-15225 | Dec 29, 2025 |
WMPro developed by Sunnet has an Arbitrary File Read vulnerabilityWMPro developed by Sunnet has an Arbitrary File Read vulnerability, allowing unauthenticated remote attackers to exploit Relative Path Traversal to read arbitrary system files. |
|
| CVE-2025-3707 | May 02, 2025 |
Sunnet eHDR CTMS Remote SQLi (CVE-2025-3707)The eHDR CTMS from Sunnet has a SQL Injection vulnerability, allowing remote attackers with regular privileges to inject arbitrary SQL command to read database contents. |
|
| CVE-2024-10440 | Oct 28, 2024 |
Sunnet eHDR CTMS SQLi Remote unauthenticated DB InjectionThe eHDR CTMS from Sunnet has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL command to read, modify, and delete database contents. |
|
| CVE-2024-10439 | Oct 28, 2024 |
Sunnet eHRD CTMS IDOR Allowing Unauth Remote Access to Uploaded FilesThe eHRD CTMS from Sunnet has an Insecure Direct Object Reference (IDOR) vulnerability, allowing unauthenticated remote attackers to modify a specific parameter to access arbitrary files uploaded by any user. |
|
| CVE-2024-10438 | Oct 28, 2024 |
Sunnet eHRD CTMS Auth Bypass (CVE-2024-10438)The eHRD CTMS from Sunnet has an Authentication Bypass vulnerability, allowing unauthenticated remote attackers to bypass authentication by satisfying specific conditions in order to access certain functionalities. |
|
| CVE-2023-35851 | Sep 18, 2023 |
SQL Injection in SUNNET WMPro FAQ FunctionSUNNET WMPro portal's FAQ function has insufficient validation for user input. An unauthenticated remote attacker can inject arbitrary SQL commands to obtain sensitive information via a database. |
|
| CVE-2023-35850 | Sep 18, 2023 |
UNVALIDATED INPUT IN SUNNET WMPro FILE MGMT ENABLING SYSTEM CMD EXECSUNNET WMPro portal's file management function has a vulnerability of insufficient filtering for user input. A remote attacker with administrator privilege or a privileged account can exploit this vulnerability to inject and execute arbitrary system commands to perform arbitrary system operations or disrupt service. |
|