Stored Cross-Site Scripting in EasyFlow .NET by Digiwin
CVE-2026-12580

5.1MEDIUM

Key Information:

Vendor

Digiwin

Vendor
CVE Published:
22 June 2026

What is CVE-2026-12580?

The software EasyFlow .NET, developed by Digiwin, is susceptible to a Stored Cross-Site Scripting vulnerability. This flaw allows authenticated remote attackers to inject persistent JavaScript code into the application, which is executed in the browsers of users upon page load. As a result, attackers can exploit this vulnerability to execute arbitrary scripts, leading to potential data theft or session hijacking for the affected users.

Affected Version(s)

EasyFlow .NET 0 <= 8.1.4

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.