VYPR

Automation

by Nintex

CVEs (3)

  • CVE-2025-27925HigMar 10, 2025
    risk 0.55cvss 8.5epss 0.00

    Nintex Automation 5.6 and 5.7 before 5.8 has insecure deserialization of user input.

  • CVE-2025-27924MedMar 10, 2025
    risk 0.35cvss 5.4epss 0.00

    Nintex Automation 5.6 and 5.7 before 5.8 has a stored XSS issue associated with the "Navigate to a URL" action.

  • CVE-2025-27926MedMar 10, 2025
    risk 0.28cvss 4.3epss 0.00

    In Nintex Automation 5.6 and 5.7 before 5.8, the K2 SmartForms Designer folder has configuration files (web.config) containing passwords that are readable by unauthorized users.