Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Update to version 4.0.0.1878.877 or later.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 13 Feb 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:flowring:agentflow:*:*:*:*:*:*:*:* |
Tue, 10 Feb 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 10 Feb 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Flowring
Flowring agentflow |
|
| Vendors & Products |
Flowring
Flowring agentflow |
Tue, 10 Feb 2026 07:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | AgentFlow developed by Flowring has a Stored Cross-Site Scripting vulnerability, allowing authenticated remote attackers to inject persistent JavaScript codes that are executed in users' browsers upon page load. | |
| Title | Flowring|AgentFlow - Stored Cross-Site Scripting | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2026-02-10T15:36:53.415Z
Reserved: 2026-02-06T11:02:51.775Z
Link: CVE-2026-2099
Updated: 2026-02-10T15:36:45.457Z
Status : Analyzed
Published: 2026-02-10T07:16:14.700
Modified: 2026-02-13T20:48:06.110
Link: CVE-2026-2099
No data.
OpenCVE Enrichment
Updated: 2026-04-17T21:00:12Z