CVE-2026-96430
- EPSS 0.23%
- Veröffentlicht 29.09.2026 09:17:11
- Zuletzt bearbeitet 29.09.2026 21:33:56
Exposed Dangerous Method or Function in the /WebAgenda/SQLWin.do API endpoint of Flowring Agentflow 4.0 version Before 2026/08/28 allows remote authenticated users to execute arbitrary SQL commands via the sql parameter.
CVE-2026-96431
- EPSS 0.28%
- Veröffentlicht 29.09.2026 09:17:11
- Zuletzt bearbeitet 29.09.2026 21:33:56
Unrestricted Upload of File with Dangerous Type in the /WebAgenda/download/uploadFile.jsp API endpoint of Flowring Agentflow 4.0 version before 2023/03/24 allows remote authenticated users to execute arbitrary system commands via a malicious file.
CVE-2026-96440
- EPSS 0.29%
- Veröffentlicht 29.09.2026 09:17:11
- Zuletzt bearbeitet 30.09.2026 16:19:26
Improper Limitation of a Pathname to a Restricted Directory(Path Traversal) in the /WebAgenda/download/uploadFile.jsp API endpoint of Flowring Agentflow 4.0 version before 2023/03/24 allows remote authenticated users to write files to arbitrary locat...
CVE-2026-96428
- EPSS 0.34%
- Veröffentlicht 29.09.2026 09:17:10
- Zuletzt bearbeitet 29.09.2026 21:33:56
SQL Injection in the /WebAgenda/SMBAjaxAutoComplete.do API endpoint of Flowring Agentflow 4.0 version before 2025/08/08 allows remote attackers to execute arbitrary SQL commands via the words parameter.
CVE-2026-96429
- EPSS 0.28%
- Veröffentlicht 29.09.2026 09:17:10
- Zuletzt bearbeitet 29.09.2026 21:33:56
SQL Injection in the /WebAgenda/SMBAjaxConfigProcess.do API endpoint of Flowring Agentflow 4.0 version before 2025/08/08 allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2026-2096
- EPSS 0.52%
- Veröffentlicht 10.02.2026 07:16:14
- Zuletzt bearbeitet 13.02.2026 20:52:16
Agentflow developed by Flowring has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to read, modify, and delete database contents by using a specific functionality.
CVE-2026-2097
- EPSS 0.44%
- Veröffentlicht 10.02.2026 07:16:14
- Zuletzt bearbeitet 13.02.2026 20:51:42
Agentflow developed by Flowring has an Arbitrary File Upload vulnerability, allowing authenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.
CVE-2026-2098
- EPSS 0.2%
- Veröffentlicht 10.02.2026 07:16:14
- Zuletzt bearbeitet 13.02.2026 20:49:31
AgentFlow developed by Flowring has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaScript codes in user's browser through phishing attacks.
CVE-2026-2099
- EPSS 0.17%
- Veröffentlicht 10.02.2026 07:16:14
- Zuletzt bearbeitet 13.02.2026 20:48:06
AgentFlow developed by Flowring has a Stored Cross-Site Scripting vulnerability, allowing authenticated remote attackers to inject persistent JavaScript codes that are executed in users' browsers upon page load.
CVE-2026-2095
- EPSS 0.51%
- Veröffentlicht 10.02.2026 07:16:13
- Zuletzt bearbeitet 13.02.2026 20:53:19
Agentflow developed by Flowring has an Authentication Bypass vulnerability, allowing unauthenticated remote attackers to exploit a specific functionality to obtain arbitrary user authentication token and log into the system as any user.