Skip to main content

Vendor archive

digiwin CVEs

Beta · best-effort

6 CVEs tagged to vendor digiwin3 Critical, 1 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2026-5964

Published Apr 20, 2026

EasyFlow .NET developed by Digiwin has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete databa…

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-5963

Published Apr 20, 2026

EasyFlow .NET developed by Digiwin has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete databa…

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2024-7323

Published Aug 2, 2024

Digiwin EasyFlow .NET lacks proper access control for specific functionality, and the functionality do not adequately filter user input. A remote attacker with regular privilege c…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-32458

Published Jul 20, 2022

Digiwin BPM has a XML External Entity Injection (XXE) vulnerability due to insufficient validation for user input. An unauthenticated remote attacker can perform XML injection att…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-32457

Published Jul 20, 2022

Digiwin BPM has inadequate filtering for URL parameter. An unauthenticated remote attacker can perform Blind SSRF attack to discover internal network topology base on URL error re…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-32456

Published Jul 20, 2022

Digiwin BPM’s function has insufficient validation for user input. An unauthenticated remote attacker can inject arbitrary SQL command to access, modify, delete database or disrup…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-6 of 6 CVEsPage 1 of 1