Stored Cross-Site Scripting in EasyFlow .NET by Digiwin
CVE-2026-12580
5.1MEDIUM
What is CVE-2026-12580?
The software EasyFlow .NET, developed by Digiwin, is susceptible to a Stored Cross-Site Scripting vulnerability. This flaw allows authenticated remote attackers to inject persistent JavaScript code into the application, which is executed in the browsers of users upon page load. As a result, attackers can exploit this vulnerability to execute arbitrary scripts, leading to potential data theft or session hijacking for the affected users.
Affected Version(s)
EasyFlow .NET 0 <= 8.1.4
