Deltaflow Project maintains a specialized data-flow orchestration product where the durable signal centers on file-handling and authentication weaknesses, including path traversal, insufficiently protected credentials, unvalidated cookie handling, and unrestricted file uploads. These input-validation and access-control patterns are characteristic of web-facing workflow platforms; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Deltaflow Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-28173CRITICAL The file upload function of Vangene deltaFlow E-platform does not perform access controlled properly. Remote attackers can upload and execute arbitrary files without login. | Apr 6, 2021 | 9.8 | 29 | NO | NO |
CVE-2021-28171CRITICAL The Vangene deltaFlow E-platform does not take properly protective measures. Attackers can obtain privileged permissions remotely by tampering with users’ data in the Cookie. | Apr 6, 2021 | 9.8 | 29 | NO | NO |
CVE-2021-28172HIGH There is a Path Traversal vulnerability in the file download function of Vangene deltaFlow E-platform. Remote attackers can access credential data with this leakage. | Apr 6, 2021 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Deltaflow Project.
Media articles that mention a CVE ID that affects a product developed by Deltaflow Project — matched by CVE ID, not by vendor name.