{"id":"CVE-2026-96430","published":"2026-09-29T09:17:11.047","lastModified":"2026-09-29T21:33:56.530","description":"Exposed Dangerous Method or Function in the\n/WebAgenda/SQLWin.do API endpoint of Flowring Agentflow 4.0 version Before 2026/08/28 allows remote\nauthenticated users to execute arbitrary SQL commands via the sql parameter.","cvssScore":null,"cvssSeverity":null,"cvssVector":null,"cwes":["CWE-749"],"vendors":[],"products":[],"references":[{"url":"https://zuso.ai/cve-advisory/advisory","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}