Known CVE
Windmill/Nextcloud Flow < 1.603.3 - Unauthenticated Path Traversal
Windmill < 1.603.3 contains a path traversal caused by unsanitized filename parameter in get_log_file endpoint, letting unauthenticated attackers read arbitrary files on the server, exploit requires no authentication.
CVE-2026-29059
Critical2026CVSS 10CWE-22
cve2026 · windmill · nextcloud · lfi · unauth · vkev
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website