Skip to content

Known CVE

Windmill/Nextcloud Flow < 1.603.3 - Unauthenticated Path Traversal

Windmill < 1.603.3 contains a path traversal caused by unsanitized filename parameter in get_log_file endpoint, letting unauthenticated attackers read arbitrary files on the server, exploit requires no authentication.

CVE-2026-29059

Critical2026CVSS 10CWE-22

cve2026 · windmill · nextcloud · lfi · unauth · vkev

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website