CVE-2025-15227
Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
29/12/2025
Last modified:
29/12/2025
Description
BPMFlowWebkit developed by WELLTEND TECHNOLOGY has a Arbitrary File Read vulnerability, allowing unauthenticated remote attackers to exploit Absolute Path Traversal to download arbitrary system files.
Impact
Base Score 4.0
8.70
Severity 4.0
HIGH
Base Score 3.x
7.50
Severity 3.x
HIGH



