Openwfe is a workflow automation engine with a narrow, focused product scope. The observed vulnerability signal centers on the engine's core offering, though the underlying weakness classification remains broad; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Openwfe over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2004-1631MEDIUM Open WorkFlow Engine (OpenWFE) 1.4.x allows remote attackers to conduct port scans of remote hosts by specifying the target in an rmi:// Worklist URL, then using the response times | Oct 25, 2004 | 5.0 | 15 | NO | NO |
CVE-2004-1630MEDIUM Cross-site scripting (XSS) vulnerability in the login form in Open WorkFlow Engine (OpenWFE) 1.4.x allows remote attackers to execute arbitrary web script or HTML via the url param | Oct 25, 2004 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Openwfe.
Media articles that mention a CVE ID that affects a product developed by Openwfe — matched by CVE ID, not by vendor name.