Vulnerability index

Browse CVEs

82 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Flowise CRITICAL 9.6
CVE-2026-42861

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass assignment vulnerability exis…

Fix: 3.1.2+
Fix from $2,300 2026-06-08
Flowise HIGH 8.1
CVE-2026-42863

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass assignment vulnerability exis…

Fix: 3.1.2+
Fix from $1,950 2026-06-08
Flowise MEDIUM 5.0
CVE-2026-42862

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass assignment vulnerability exis…

Fix: 3.1.2+
Fix from $1,600 2026-06-08
Flowise CRITICAL 9.8
CVE-2026-43995

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, multiple tool implementations directly impor…

Fix: 3.1.0+
Fix from $2,300 2026-05-11
Flowise MEDIUM 5.3
CVE-2026-8026

A security flaw has been discovered in FlowiseAI Flowise up to 3.0.12. Affected is the function Login of the file packages/server/src/enterprise/serv…

Fix: after 3.0.12
Fix from $1,600 2026-05-06
Flowise CRITICAL 9.8
CVE-2026-41274

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the GraphCypherQAChain node forwards user-pr…

Fix: 3.1.0+
Fix from $2,300 2026-04-23
Flowise CRITICAL 9.8
CVE-2026-41276EPSS 7%

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, this vulnerability allows remote attackers t…

Fix: 3.1.0+
Fix from $2,300 2026-04-23
Flowise HIGH 8.8
CVE-2026-41277

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, a Mass Assignment vulnerability in the Docum…

Fix: 3.1.0+
Fix from $1,950 2026-04-23
Flowise HIGH 7.5
CVE-2026-41275

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the password reset functionality on cloud.fl…

Fix: 3.1.0+
Fix from $1,950 2026-04-23
Flowise HIGH 7.5
CVE-2026-41278

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the GET /api/v1/public-chatflows/:id endpoin…

Fix: 3.1.0+
Fix from $1,950 2026-04-23
Flowise HIGH 7.5
CVE-2026-41279

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the text-to-speech generation endpoint (POST…

Fix: 3.1.0+
Fix from $1,950 2026-04-23
Flowise CRITICAL 9.8
CVE-2026-41267

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, an improper mass assignment (JSON injection)…

Fix: 3.1.0+
Fix from $2,300 2026-04-23
Flowise CRITICAL 9.8
CVE-2026-41268EPSS 14%

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, Flowise is vulnerable to a critical unauthen…

Fix: 3.1.0+
Fix from $2,300 2026-04-23
Flowise HIGH 8.8
CVE-2026-41269

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the Chatflow configuration file upload setti…

Fix: 3.1.0+
Fix from $1,950 2026-04-23
Flowise HIGH 8.3
CVE-2026-41270

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, a Server-Side Request Forgery (SSRF) protect…

Fix: 3.1.0+
Fix from $1,950 2026-04-23
Flowise HIGH 8.3
CVE-2026-41271

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, a Server-Side Request Forgery (SSRF) vulnera…

Fix: 3.1.0+
Fix from $1,950 2026-04-23
Flowise HIGH 8.2
CVE-2026-41273

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, Flowise contains an authentication bypass vu…

Fix: 3.1.0+
Fix from $1,950 2026-04-23
Flowise HIGH 7.5
CVE-2026-41266

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, /api/v1/public-chatbotConfig/:id ep exposes …

Fix: 3.1.0+
Fix from $1,950 2026-04-23
Flowise HIGH 7.1
CVE-2026-41272

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the core security wrappers (secureAxiosReque…

Fix: 3.1.0+
Fix from $1,950 2026-04-23
Flowise CRITICAL 9.8
CVE-2026-41264

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the specific flaw exists within the run meth…

Fix: 3.1.0+
Fix from $2,300 2026-04-23
Flowise CRITICAL 9.8
CVE-2026-41265

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the specific flaw exists within the run meth…

Fix: 3.1.0+
Fix from $2,300 2026-04-23
Flowise HIGH 8.8
CVE-2026-41137

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, The CSVAgent allows providing a custom Panda…

Fix: 3.1.0+
Fix from $1,950 2026-04-23
Flowise HIGH 8.8
CVE-2026-41138

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, there is a remote code execution vulnerabili…

Fix: 3.1.0+
Fix from $1,950 2026-04-23
Flowise CRITICAL 9.9
CVE-2026-40933EPSS 13%

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, due to unsafe serialization of stdio command…

Fix: 3.1.0+
Fix from $2,300 2026-04-21
Flowise HIGH 8.8
CVE-2026-31829

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.0.13, Flowise exposes an HTTP Node in AgentFlow a…

Fix: 3.0.13+
Fix from $1,950 2026-03-10
Flowise CRITICAL 9.8
CVE-2026-30824EPSS 36%

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, the NVIDIA NIM router (/api/v1/nvid…

Fix: 3.0.13+
Fix from $2,300 2026-03-07
Flowise HIGH 8.8
CVE-2026-30823

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, there is an IDOR vulnerability, lea…

Fix: 3.0.13+
Fix from $1,950 2026-03-07
Flowise HIGH 7.7
CVE-2026-30822EPSS 13%

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, unauthenticated users can inject ar…

Fix: 3.0.13+
Fix from $1,950 2026-03-07
Flowise CRITICAL 9.8
CVE-2026-30821EPSS 15%

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, the /api/v1/attachments/:chatflowId…

Fix: 3.0.13+
Fix from $2,300 2026-03-07
Flowise HIGH 8.8
CVE-2026-30820

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, Flowise trusts any HTTP client that…

Fix: 3.0.13+
Fix from $1,950 2026-03-07