Home/Product/flowring agentflow
Product

flowring agentflow

9 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-2099
< 4.0.0.1878.877
AgentFlow developed by Flowring has a Stored Cross-Site Scripting vulnerability, allowing authenticated remote attackers to inject
5.4MEDIUM
CVE-2026-2098
< 4.0.0.1878.877
AgentFlow developed by Flowring has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to e
6.1MEDIUM
CVE-2026-2097
all versions
Agentflow developed by Flowring has an Arbitrary File Upload vulnerability, allowing authenticated remote attackers to upload and
8.8HIGH
CVE-2026-2096
all versions
Agentflow developed by Flowring has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to read, mod
9.8CRITICAL
CVE-2026-2095
all versions
Agentflow developed by Flowring has an Authentication Bypass vulnerability, allowing unauthenticated remote attackers to exploit a
9.8CRITICAL
CVE-2025-3709
all versions
Agentflow from Flowring Technology has an Account Lockout Bypass vulnerability, allowing unauthenticated remote attackers to explo
9.8CRITICAL
CVE-2022-39038
all versions
Agentflow BPM enterprise management system has improper authentication. A remote attacker with general user privilege can change t
8.8HIGH
CVE-2022-39037
all versions
Agentflow BPM file download function has a path traversal vulnerability. An unauthenticated remote attacker can exploit this vulne
7.5HIGH
CVE-2022-39036
all versions
The file upload function of Agentflow BPM has insufficient filtering for special characters in URLs. An unauthenticated remote att
9.8CRITICAL
threatengine.sh