All 4 CVE vulnerabilities found in Flow, with AI-generated Chinese analysis, references, and POCs.
Vendor: Total.js
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-57793 | WordPress Flow theme <= 1.8 - Local File Inclusion vulnerability CWE-98 | 7.5 | High | 2026-07-13 |
| CVE-2026-7860 | Possible information disclosure of environment variables in Vaadin Build Plugins via Failed Frontend Build CWE-209 | - | - | 2026-05-19 |
| CVE-2026-1126 | lwj flow SVG File FormResource.java uploadFile unrestricted upload CWE-434 | 6.3 | Medium | 2026-01-18 |
| CVE-2025-11655 | Total.js Flow SVG File unrestricted upload CWE-434 | 4.7 | Medium | 2025-10-13 |
All 4 known CVE vulnerabilities affecting Flow with full Chinese analysis, references, and POCs where available.