Itflow
Itflow-Org · 3 CVEs
CVE-2026-54597
HIGH
ITFlow: Authenticated Time-Based Blind SQL Injection in ITFlow via expires Parameter
Sep 17, 2026
CVE-2026-54596
HIGH
ITFlow: Authenticated SQL Injection via recurring_invoice_frequency Parameter Enables Full Database Exfiltration
Sep 17, 2026
CVE-2026-47755
MEDIUM
ITFlow Vulnerable to Authenticated Cross-Tenant Credential Disclosure via Unprotected Credential Modal
Jul 23, 2026
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-54597 | ITFlow: Authenticated Time-Based Blind SQL Injection in ITFlow via expires Parameter | HIGH | 0.43% | Sep 17, 2026 |
| CVE-2026-54596 | ITFlow: Authenticated SQL Injection via recurring_invoice_frequency Parameter Enables Full Database Exfiltration | HIGH | 0.48% | Sep 17, 2026 |
| CVE-2026-47755 | ITFlow Vulnerable to Authenticated Cross-Tenant Credential Disclosure via Unprotected Credential Modal | MEDIUM | 0.35% | Jul 23, 2026 |
Showing 1 to 3 of 3 CVEs