Tim Solutions maintains a narrowly focused product portfolio centered on Tim Flow, a workflow or process-automation application that, despite limited disclosure volume, operates in environments where it carries operational significance. The durable signal from observed vulnerabilities remains sparse; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tim Solutions over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-67278MEDIUM An issue in TIM Solution GmbH TIM BPM Suite & TIM FLOW before v.9.1.2 allows a remote attacker to escalate privileges via a crafted HTTP request | Jan 9, 2026 | 6.5 | 22 | NO | NO |
CVE-2025-67282MEDIUM In TIM BPM Suite/ TIM FLOW through 9.1.2 multiple Authorization Bypass vulnerabilities exists which allow a low privileged user to download password hashes of other user, access wo | Jan 9, 2026 | 5.4 | 19 | NO | NO |
CVE-2025-67281MEDIUM In TIM BPM Suite/ TIM FLOW through 9.1.2 multiple SQL injection vulnerabilities exists which allow a low privileged and administrative user to access the database and its content. | Jan 9, 2026 | 5.4 | 19 | NO | NO |
CVE-2025-67280MEDIUM In TIM BPM Suite/ TIM FLOW through 9.1.2 multiple Hibernate Query Language injection vulnerabilities exist which allow a low privileged user to extract passwords of other users and | Jan 9, 2026 | 5.4 | 19 | NO | NO |
CVE-2025-67279MEDIUM An issue in TIM Solution GmbH TIM BPM Suite & TIM FLOW before v.9.1.2 allows a remote attacker to escalate privileges via the application stores password hashes in MD5 format | Jan 9, 2026 | 5.3 | 19 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tim Solutions.
Media articles that mention a CVE ID that affects a product developed by Tim Solutions — matched by CVE ID, not by vendor name.