« Back to list

Digiwin

Digiwin Easyflow: vulnerabilities and CVEs

Digiwin Easyflow has 4 published vulnerabilities, 4 of them in the last 12 months. 1 are rated critical and 0 are listed by CISA as actively exploited.

CVEs4
Last 12 months4
Critical1
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-102457High (7.1)0.38%—Sep 30, 2026
EasyFlow .NET developed by Digiwin has an Arbitrary File Read vulnerability. Authenticated remote attackers can exploit this vulnerability to download arbitrary system files.
CVE-2026-102456High (7.1)0.27%—Sep 30, 2026
EasyFlow .NET developed by Digiwin has an SQL Injection vulnerability. Authenticated remote attackers can inject arbitrary SQL commands to read database contents.
CVE-2026-102455Critical (9.3)0.51%—Sep 30, 2026
EasyFlow .NET developed by Digiwin has a Insecure Deserialization vulnerability. Unauthenticated remote attackers can execute arbitrary code on the server by sending maliciously crafted serialized content.
CVE-2026-102454High (8.6)0.56%—Sep 30, 2026
EasyFlow .NET developed by Digiwin has an Arbitrary File Upload vulnerability. Privileged remote attackers can upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.

🎯 How it gets exploited (ATT&CK techniques)

  1. T1210 Exploitation of Remote Services3
  2. T1005 Data from Local System2
  3. T1059 Command and Scripting Interpreter1
  4. T1190 Exploit Public-Facing Application1
  5. T1505.003 Web Shell1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Digiwin