CVE-2026-102456: high-severity vulnerability in DigiWin EasyFlow .NET
DigiWin|EasyFlow .NET - SQL Injection
Published
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.1epss 0.3%
exploitation probability
0.3%top 82% of all CVEs
observed exploitation
nono source reports it
EasyFlow .NET developed by Digiwin has an SQL Injection vulnerability. Authenticated remote attackers can inject arbitrary SQL commands to read database contents.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Affected products
DigiWin · EasyFlow .NETRelated CVEs — DigiWin EasyFlow .NET
In the same product, most dangerous first.
CVE-2024-4893CRITICALDigiWin EasyFlow .NET - SQL InjectionEPSS 0.8%CVE-2024-5311CRITICALDigiWin EasyFlow .NET - SQL InjectionEPSS 0.6%CVE-2026-102454HIGHDigiWin|EasyFlow .NET - Arbitrary File UploadEPSS 0.6%CVE-2026-102455CRITICALDigiWin|EasyFlow .NET - Insecure DeserializationEPSS 0.5%CVE-2026-102458CRITICALDigiWin|EasyFlow .NET - Missing AuthenticationEPSS 0.4%CVE-2026-102457HIGHDigiWin|EasyFlow .NET - Arbitrary File ReadEPSS 0.4%