Vendor
Nintex
Products
8
CVEs
5
Across products
12
Status
Private
Products
8- 3 CVEs
- 3 CVEs
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
Recent CVEs
5| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-27925 | Hig | 0.55 | 8.5 | 0.00 | Mar 10, 2025 | Nintex Automation 5.6 and 5.7 before 5.8 has insecure deserialization of user input. | ||
| CVE-2022-38167 | Med | 0.40 | 6.1 | 0.00 | Nov 14, 2022 | The Nintex Workflow plugin 5.2.2.30 for SharePoint allows XSS. | ||
| CVE-2025-27924 | Med | 0.35 | 5.4 | 0.00 | Mar 10, 2025 | Nintex Automation 5.6 and 5.7 before 5.8 has a stored XSS issue associated with the "Navigate to a URL" action. | ||
| CVE-2025-27926 | Med | 0.28 | 4.3 | 0.00 | Mar 10, 2025 | In Nintex Automation 5.6 and 5.7 before 5.8, the K2 SmartForms Designer folder has configuration files (web.config) containing passwords that are readable by unauthorized users. | ||
| CVE-2015-7299 | 0.00 | — | 0.02 | Oct 21, 2015 | SQL injection vulnerability in Runtime/Runtime/AjaxCall.ashx in K2 blackpearl, smartforms, and K2 for SharePoint 4.6.7 allows remote attackers to execute arbitrary SQL commands via the xml parameter. |
- risk 0.55cvss 8.5epss 0.00
Nintex Automation 5.6 and 5.7 before 5.8 has insecure deserialization of user input.
- risk 0.40cvss 6.1epss 0.00
The Nintex Workflow plugin 5.2.2.30 for SharePoint allows XSS.
- risk 0.35cvss 5.4epss 0.00
Nintex Automation 5.6 and 5.7 before 5.8 has a stored XSS issue associated with the "Navigate to a URL" action.
- risk 0.28cvss 4.3epss 0.00
In Nintex Automation 5.6 and 5.7 before 5.8, the K2 SmartForms Designer folder has configuration files (web.config) containing passwords that are readable by unauthorized users.
- CVE-2015-7299Oct 21, 2015risk 0.00cvss —epss 0.02
SQL injection vulnerability in Runtime/Runtime/AjaxCall.ashx in K2 blackpearl, smartforms, and K2 for SharePoint 4.6.7 allows remote attackers to execute arbitrary SQL commands via the xml parameter.