CVE-2026-102456Medium· 6.5▾ SunlitEasyFlow .NET developed by Digiwin has an SQL Injection vulnerability. Authenticated remote attackers can inject arbitrary SQL commands to read database contents.
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
EasyFlow .NET developed by Digiwin has an SQL Injection vulnerability. Authenticated remote attackers can inject arbitrary SQL commands to read database contents.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-102455Critical· 9.8EasyFlow .NET developed by Digiwin has a Insecure Deserialization vulnerability
CVE-2026-102457Medium· 6.5EasyFlow .NET developed by Digiwin has an Arbitrary File Read vulnerability
CVE-2026-102458Critical· 9.8EasyFlow .NET developed by Digiwin has a Missing Authentication vulnerability
CVE-2026-102459Medium· 6.1EasyFlow .NET developed by Digiwin has a Reflected Cross-site Scripting vulnerability
CVE-2026-102454High· 7.2EasyFlow .NET developed by Digiwin has an Arbitrary File Upload vulnerability
CVE-2025-14666High· 7.3A weakness has been identified in itsourcecode COVID Tracking System 1.0