Newtype develops business process management and enterprise integration platforms, notably FlowMaster BPM Plus and WebEIP, which handle application logic and data flow across enterprise environments. The recurring vulnerability signal centers on web application input handling, with observed weaknesses spanning SQL injection, cross-site scripting, and insufficient session validation—patterns typical of server-side applications processing untrusted user input and managing authentication state. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Newtype over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-9971HIGH The specific query functionality in the FlowMaster BPM Plus from NewType does not properly restrict user input, allowing remote attackers with regular privileges to inject SQL comm | Oct 15, 2024 | 8.8 | 25 | NO | NO |
CVE-2024-9970HIGH The FlowMaster BPM Plus system from NewType has a privilege escalation vulnerability. Remote attackers with regular privileges can elevate their privileges to administrator by tamp | Oct 15, 2024 | 8.8 | 25 | NO | NO |
CVE-2024-9968HIGH WebEIP v3.0 from
NewType does not properly validate user input, allowing remote attackers with regular privilege to inject SQL commands to read, modify, and delete data stored in | Oct 15, 2024 | 8.8 | 25 | NO | NO |
CVE-2024-9969MEDIUM NewType WebEIP v3.0 does not properly validate user input, allowing a remote attacker with regular privileges to insert JavaScript into specific parameters, resulting in a Reflecte | Oct 15, 2024 | 5.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Newtype.
Media articles that mention a CVE ID that affects a product developed by Newtype — matched by CVE ID, not by vendor name.