cbcvebase.

Flowring Technology Corp Agentflow 4.0 vulnerabilities

5 known vulnerabilities affecting flowring_technology_corp/agentflow_4.0.

Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH2

Vulnerabilities

Page 1 of 1
CVE-2026-96428P2CRITICALCVSS 9.3fixed in 2025/08/082026-09-29
CVE-2026-96428 [CRITICAL] CWE-89 CVE-2026-96428: SQL Injection in the /WebAgenda/SMBAjaxAutoComplete.do API endpoint of Flowring Agentflow 4.0 versio SQL Injection in the /WebAgenda/SMBAjaxAutoComplete.do API endpoint of Flowring Agentflow 4.0 version before 2025/08/08 allows remote attackers to execute arbitrary SQL commands via the words parameter.
nvd
CVE-2026-96431P2CRITICALCVSS 9.3fixed in 2023/03/242026-09-29
CVE-2026-96431 [CRITICAL] CWE-434 CVE-2026-96431: Unrestricted Upload of File with Dangerous Type in the /WebAgenda/download/uploadFile.jsp API endpoi Unrestricted Upload of File with Dangerous Type in the /WebAgenda/download/uploadFile.jsp API endpoint of Flowring Agentflow 4.0 version before 2023/03/24 allows remote authenticated users to execute arbitrary system commands via a malicious file.
nvd
CVE-2026-96429P2CRITICALCVSS 9.3fixed in 2025/08/082026-09-29
CVE-2026-96429 [CRITICAL] CWE-89 CVE-2026-96429: SQL Injection in the /WebAgenda/SMBAjaxConfigProcess.do API endpoint of Flowring Agentflow 4.0 versi SQL Injection in the /WebAgenda/SMBAjaxConfigProcess.do API endpoint of Flowring Agentflow 4.0 version before 2025/08/08 allows remote attackers to execute arbitrary SQL commands via the id parameter.
nvd
CVE-2026-96430P3HIGHCVSS 8.7fixed in 2026/08/282026-09-29
CVE-2026-96430 [HIGH] CWE-749 CVE-2026-96430: Exposed Dangerous Method or Function in the /WebAgenda/SQLWin.do API endpoint of Flowring Agentflow Exposed Dangerous Method or Function in the /WebAgenda/SQLWin.do API endpoint of Flowring Agentflow 4.0 version Before 2026/08/28 allows remote authenticated users to execute arbitrary SQL commands via the sql parameter.
nvd
CVE-2026-96440P3HIGHCVSS 7.1fixed in 2023/03/242026-09-29
CVE-2026-96440 [HIGH] CWE-22 CVE-2026-96440: Improper Limitation of a Pathname to a Restricted Directory(Path Traversal) in the /WebAgenda/downlo Improper Limitation of a Pathname to a Restricted Directory(Path Traversal) in the /WebAgenda/download/uploadFile.jsp API endpoint of Flowring Agentflow 4.0 version before 2023/03/24 allows remote authenticated users to write files to arbitrary locations outside the intended upload directory via the path parameter.
nvd
Flowring Technology Corp Agentflow 4.0 vulnerabilities | cvebase