Digiwin's vulnerability footprint centers on enterprise business process management and workflow automation software serving mid-market and larger organizations, a critical position in business-critical application stacks. Its disclosed vulnerabilities skew strongly toward critical-severity outcomes and recur through a consistent pattern of input-handling and access-control weaknesses—SQL injection, path traversal, XML entity expansion, and server-side request forgery—that reflect the data-integration and document-processing demands of workflow platforms. Defenders should treat this vendor's advisories as high-priority given the criticality of affected systems and the severity profile; live exploitation activity and detailed exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Digiwin over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-5964CRITICAL EasyFlow .NET developed by Digiwin has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete databas | Apr 20, 2026 | 9.8 | 33 | NO | NO |
CVE-2026-5963CRITICAL EasyFlow .NET developed by Digiwin has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete databas | Apr 20, 2026 | 9.8 | 33 | NO | NO |
CVE-2026-12581HIGH EasyFlow .NET developed by Digiwin has a Session Fixation vulnerability. If unauthenticated remote attackers replace a specific session ID for a user, they can gain the user's priv | Jun 22, 2026 | 7.5 | 30 | NO | NO |
CVE-2022-32456CRITICAL Digiwin BPM’s function has insufficient validation for user input. An unauthenticated remote attacker can inject arbitrary SQL command to access, modify, delete database or disrupt | Jul 20, 2022 | 9.8 | 30 | NO | NO |
CVE-2026-12580MEDIUM EasyFlow .NET developed by Digiwin has a Stored Cross-Site Scripting vulnerability, allowing authenticated remote attackers to inject persistent JavaScript code executed in users' | Jun 22, 2026 | 5.4 | 25 | NO | NO |
CVE-2022-32458HIGH Digiwin BPM has a XML External Entity Injection (XXE) vulnerability due to insufficient validation for user input. An unauthenticated remote attacker can perform XML injection atta | Jul 20, 2022 | 7.5 | 25 | NO | NO |
CVE-2022-32457MEDIUM Digiwin BPM has inadequate filtering for URL parameter. An unauthenticated remote attacker can perform Blind SSRF attack to discover internal network topology base on URL error res | Jul 20, 2022 | 5.3 | 20 | NO | NO |
CVE-2024-7323MEDIUM Digiwin EasyFlow .NET lacks proper access control for specific functionality, and the functionality do not adequately filter user input. A remote attacker with regular privilege ca | Aug 2, 2024 | 6.5 | 18 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Digiwin.
Media articles that mention a CVE ID that affects a product developed by Digiwin — matched by CVE ID, not by vendor name.