Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Update to version 5.0.5 or later.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 31 Dec 2025 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Welltend
Welltend bpmflowwebkit |
|
| Weaknesses | CWE-22 | |
| CPEs | cpe:2.3:a:welltend:bpmflowwebkit:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Welltend
Welltend bpmflowwebkit |
Mon, 29 Dec 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 29 Dec 2025 07:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | BPMFlowWebkit developed by WELLTEND TECHNOLOGY has a Arbitrary File Read vulnerability, allowing unauthenticated remote attackers to exploit Absolute Path Traversal to download arbitrary system files. | |
| Title | WELLTEND TECHNOLOGY| BPMFlowWebkit - Arbitrary File Read | |
| Weaknesses | CWE-36 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2025-12-29T14:31:48.689Z
Reserved: 2025-12-29T06:12:33.769Z
Link: CVE-2025-15227
Updated: 2025-12-29T14:30:09.593Z
Status : Analyzed
Published: 2025-12-29T08:15:51.650
Modified: 2025-12-31T20:32:55.480
Link: CVE-2025-15227
No data.
OpenCVE Enrichment
No data.