CVE-2026-5963: Digiwin Easyflow .net
Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.
EasyFlow .NET developed by Digiwin has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.
Affected products
- Digiwin Easyflow .net: from 6.6.0, up to and including 6.6.17; version 6.1.0 only; version 8.1.1 only; version 8.1.2 only; version 8.1.3 only; version 8.1.4 only
Published 2026-04-20. Last modified 2026-06-17.