Nintex is a niche automation and workflow platform vendor whose products, including its K2 suite and smartforms offerings, integrate with enterprise SharePoint and business-process environments. The vendor's vulnerability footprint centers on application-layer weaknesses characteristic of web-facing workflow systems: cross-site scripting, SQL injection, untrusted deserialization, credential handling, and permission-configuration issues. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Nintex over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-27925CRITICAL Nintex Automation 5.6 and 5.7 before 5.8 has insecure deserialization of user input. | Mar 10, 2025 | 9.8 | 27 | NO | NO |
CVE-2022-38167MEDIUM The Nintex Workflow plugin 5.2.2.30 for SharePoint allows XSS. | Nov 14, 2022 | 6.1 | 21 | NO | NO |
CVE-2015-7299HIGH SQL injection vulnerability in Runtime/Runtime/AjaxCall.ashx in K2 blackpearl, smartforms, and K2 for SharePoint 4.6.7 allows remote attackers to execute arbitrary SQL commands via | Oct 21, 2015 | 7.5 | 20 | NO | NO |
CVE-2025-27926MEDIUM In Nintex Automation 5.6 and 5.7 before 5.8, the K2 SmartForms Designer folder has configuration files (web.config) containing passwords that are readable by unauthorized users. | Mar 10, 2025 | 5.3 | 17 | NO | NO |
CVE-2025-27924MEDIUM Nintex Automation 5.6 and 5.7 before 5.8 has a stored XSS issue associated with the "Navigate to a URL" action. | Mar 10, 2025 | 5.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Nintex.
Media articles that mention a CVE ID that affects a product developed by Nintex — matched by CVE ID, not by vendor name.