Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Update to version 5.0.5 or later.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 31 Dec 2025 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Welltend
Welltend bpmflowwebkit |
|
| CPEs | cpe:2.3:a:welltend:bpmflowwebkit:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Welltend
Welltend bpmflowwebkit |
Mon, 29 Dec 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 29 Dec 2025 07:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | BPMFlowWebkit developed by WELLTEND TECHNOLOGY has a Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server. | |
| Title | WELLTEND TECHNOLOGY| BPMFlowWebkit - Arbitrary File Upload | |
| Weaknesses | CWE-434 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2025-12-29T16:45:14.701Z
Reserved: 2025-12-29T06:12:35.218Z
Link: CVE-2025-15228
Updated: 2025-12-29T16:45:06.234Z
Status : Analyzed
Published: 2025-12-29T08:15:51.820
Modified: 2025-12-31T20:31:32.903
Link: CVE-2025-15228
No data.
OpenCVE Enrichment
No data.