CVE-2026-12580
Received Received - Intake
Stored XSS in EasyFlow .NET Application

Publication date: 2026-06-22

Last updated on: 2026-06-22

Assigner: TWCERT/CC

Description
EasyFlow .NET developed by Digiwin has a Stored Cross-Site Scripting vulnerability, allowing authenticated remote attackers to inject persistent JavaScript code executed in users' browsers upon page load.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-22
Last Modified
2026-06-22
Generated
2026-06-22
AI Q&A
2026-06-22
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
digiwin easyflow to 8.1.5 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

CVE-2026-12580 is a Stored Cross-Site Scripting (XSS) vulnerability in Digiwin EasyFlow .NET versions 8.1.4 and earlier.

This flaw allows authenticated remote attackers to inject persistent JavaScript code into specific pages.

The injected code executes automatically in users' browsers when they load the affected pages.

Impact Analysis

The vulnerability allows attackers who have authentication to the system to inject malicious JavaScript code that will run in the browsers of other users viewing the affected pages.

This can lead to unauthorized actions performed on behalf of users, data theft, session hijacking, or other malicious activities executed in the context of the user's browser.

Exploitation requires user interaction, meaning the victim must load the affected page for the attack to succeed.

The vulnerability has a medium severity with a CVSS score around 5.4.

Mitigation Strategies

To mitigate the Stored Cross-Site Scripting vulnerability in Digiwin EasyFlow .NET, users should update the software to version 8.1.5 or later.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-12580. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart