CVE-2025-13175: Ysoft Safeq 6

Medium severity, CVSS 5.1. EPSS: 0.3% chance of exploitation in the next 30 days.

Y Soft SafeQ 6 renders the Workflow Connector password field in a way that allows an administrator with UI access to reveal the value using browser developer/inspection tools. The affected customers are only those with a password-protected scan workflow connector. This issue affects Y Soft SafeQ 6 in versions before MU106.

Affected products

Published 2026-01-14. Last modified 2026-06-17.