{"id":"CVE-2026-96428","published":"2026-09-29T09:17:10.687","lastModified":"2026-09-29T21:33:56.530","description":"SQL Injection in the /WebAgenda/SMBAjaxAutoComplete.do API endpoint of Flowring Agentflow 4.0 version before 2025/08/08 allows remote attackers to execute arbitrary SQL commands via the words parameter.","cvssScore":null,"cvssSeverity":null,"cvssVector":null,"cwes":["CWE-89"],"vendors":[],"products":[],"references":[{"url":"https://zuso.ai/cve-advisory/advisory","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}