Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Digiwin

First CVE: Jul 20, 2022Active for: 4 yearsTotal CVEs: 8

Digiwin's vulnerability footprint centers on enterprise business process management and workflow automation software serving mid-market and larger organizations, a critical position in business-critical application stacks. Its disclosed vulnerabilities skew strongly toward critical-severity outcomes and recur through a consistent pattern of input-handling and access-control weaknesses—SQL injection, path traversal, XML entity expansion, and server-side request forgery—that reflect the data-integration and document-processing demands of workflow platforms. Defenders should treat this vendor's advisories as high-priority given the criticality of affected systems and the severity profile; live exploitation activity and detailed exposure counts are shown alongside this summary.

FAUCET AI Generated
8
Total CVEs
More Total CVEs than 90% of tracked vendors
1.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 76% of tracked vendors
7.7
Avg CVSS Score
Higher Avg CVSS Score than 73% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Digiwin over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 20, 2022
4 years ago
Most Recent CVE
Jun 22, 2026
32 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (8 CVEs).

8 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-5964CRITICAL
EasyFlow .NET developed by Digiwin has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete databas
Apr 20, 20269.833NONO
CVE-2026-5963CRITICAL
EasyFlow .NET developed by Digiwin has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete databas
Apr 20, 20269.833NONO
CVE-2026-12581HIGH
EasyFlow .NET developed by Digiwin has a Session Fixation vulnerability. If unauthenticated remote attackers replace a specific session ID for a user, they can gain the user's priv
Jun 22, 20267.530NONO
CVE-2022-32456CRITICAL
Digiwin BPM’s function has insufficient validation for user input. An unauthenticated remote attacker can inject arbitrary SQL command to access, modify, delete database or disrupt
Jul 20, 20229.830NONO
CVE-2026-12580MEDIUM
EasyFlow .NET developed by Digiwin has a Stored Cross-Site Scripting vulnerability, allowing authenticated remote attackers to inject persistent JavaScript code executed in users'
Jun 22, 20265.425NONO
CVE-2022-32458HIGH
Digiwin BPM has a XML External Entity Injection (XXE) vulnerability due to insufficient validation for user input. An unauthenticated remote attacker can perform XML injection atta
Jul 20, 20227.525NONO
CVE-2022-32457MEDIUM
Digiwin BPM has inadequate filtering for URL parameter. An unauthenticated remote attacker can perform Blind SSRF attack to discover internal network topology base on URL error res
Jul 20, 20225.320NONO
CVE-2024-7323MEDIUM
Digiwin EasyFlow .NET lacks proper access control for specific functionality, and the functionality do not adequately filter user input. A remote attacker with regular privilege ca
Aug 2, 20246.518NONO
View all 8 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products8 CVEs
38%
25%
38%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network8 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (87.5%)
High1 (12.5%)
Unknown0 (0.0%)
User Interaction
None6 (75.0%)
Unknown0 (0.0%)
Required2 (25.0%)
Privileges Required
Low2 (25.0%)
High0 (0.0%)
None6 (75.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (8 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Digiwin.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Digiwin — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Digiwin's Products

View all 1 CNAs →

Top CWEs