CVE-2026-102459Medium· 6.1▾ SunlitEasyFlow .NET developed by Digiwin has a Reflected Cross-site Scripting vulnerability. Unauthenticated remote attackers can execute arbitrary JavaScript codes in user's browser through phishing attacks.
▾ Sunlit zone — Low / medium · no exploitation signal
impact 33.6 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
EasyFlow .NET developed by Digiwin has a Reflected Cross-site Scripting vulnerability. Unauthenticated remote attackers can execute arbitrary JavaScript codes in user's browser through phishing attacks.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-102455Critical· 9.8EasyFlow .NET developed by Digiwin has a Insecure Deserialization vulnerability
CVE-2026-102457Medium· 6.5EasyFlow .NET developed by Digiwin has an Arbitrary File Read vulnerability
CVE-2026-102458Critical· 9.8EasyFlow .NET developed by Digiwin has a Missing Authentication vulnerability
CVE-2026-102456Medium· 6.5EasyFlow .NET developed by Digiwin has an SQL Injection vulnerability
CVE-2026-102454High· 7.2EasyFlow .NET developed by Digiwin has an Arbitrary File Upload vulnerability
CVE-2021-41164High· 8.2CKEditor4 is an open source WYSIWYG HTML editor