CVE-2026-5964: Digiwin Easyflow .net

Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.

EasyFlow .NET developed by Digiwin has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.

Affected products

  • Digiwin Easyflow .net: from 6.6.0, up to and including 6.6.17; version 6.1.0 only; version 8.1.1 only; version 8.1.2 only

Published 2026-04-20. Last modified 2026-06-17.