CVE-2024-7098: Sfs Winsure

Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.

Improper Restriction of XML External Entity Reference vulnerability in SFS Consulting ww.Winsure allows XML Injection. This issue affects ww.Winsure: before 4.6.2.

Affected products

  • Sfs Winsure: before 4.6.2 (fixed in 4.6.2)

Published 2024-09-16. Last modified 2026-06-17.