{"id":"CVE-2026-96429","published":"2026-09-29T09:17:10.917","lastModified":"2026-09-29T21:33:56.530","description":"SQL Injection in the /WebAgenda/SMBAjaxConfigProcess.do API\nendpoint of Flowring Agentflow 4.0 version before 2025/08/08 allows\nremote attackers to execute arbitrary SQL commands via the id parameter.","cvssScore":null,"cvssSeverity":null,"cvssVector":null,"cwes":["CWE-89"],"vendors":[],"products":[],"references":[{"url":"https://zuso.ai/cve-advisory/advisory","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}