Vulnerability index

Browse CVEs

82 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Flowise MEDIUM 6.5
CVE-2025-57164

Flowise through v3.0.4 is vulnerable to remote code execution via unsanitized evaluation of user input in the "Supabase RPC Filter" field.

No fix yet
Fix from $1,600 2025-10-17
Flowise CRITICAL 9.9
CVE-2025-34267EPSS 6%

Flowise v3.0.1 < 3.0.8 and all versions after with 'ALLOW_BUILTIN_DEP' enabled contain an authenticated remote code execution vulnerability and node …

Fix: 3.0.8+
Fix from $2,300 2025-10-14
Flowise CRITICAL 9.9
CVE-2025-61913EPSS 12%

Flowise is a drag & drop user interface to build a customized large language model flow. In versions prior to 3.0.8, WriteFileTool and ReadFileTool i…

Fix: 3.0.8+
Fix from $2,300 2025-10-08
Flowise HIGH 8.8
CVE-2025-61687EPSS 10%

Flowise is a drag & drop user interface to build a customized large language model flow. A file upload vulnerability in version 3.0.7 of FlowiseAI al…

No fix yet
Fix from $1,950 2025-10-06
Flowise MEDIUM 6.1
CVE-2025-29192

Flowise before 3.0.5 allows XSS via a FORM element and an INPUT element when an admin views the chat log.

Fix: 3.0.5+
Fix from $1,600 2025-10-06
Flowise MEDIUM 6.1
CVE-2025-50538EPSS 13%

Flowise before 3.0.5 allows XSS via an IFRAME element when an admin views the chat log.

Fix: 3.0.5+
Fix from $1,600 2025-10-06
Flowise CRITICAL 10.0
CVE-2025-59528EPSS 90%

Flowise is a drag & drop user interface to build a customized large language model flow. In version 3.0.5, Flowise is vulnerable to remote code execu…

Mitigation only
Fix from $2,300 2025-09-22
Flowise HIGH 7.5
CVE-2025-59527

Flowise is a drag & drop user interface to build a customized large language model flow. In version 3.0.5, a Server-Side Request Forgery (SSRF) vulne…

No fix yet
Fix from $1,950 2025-09-22
Flowise CRITICAL 9.8
CVE-2025-58434EPSS 50%

Flowise is a drag & drop user interface to build a customized large language model flow. In version 3.0.5 and earlier, the `forgot-password` endpoint…

Fix: 3.0.6+
Fix from $2,300 2025-09-12
Flowise CRITICAL 9.8
CVE-2025-8943EPSS 72%

The Custom MCPs feature is designed to execute OS commands, for instance, using tools like `npx` to spin up local MCP Servers. However, Flowise's inh…

Fix: 3.0.1+
Fix from $2,300 2025-08-14
Flowise HIGH 7.6
CVE-2025-29189

Flowise <= 2.2.3 is vulnerable to SQL Injection. via tableName parameter at Postgres_VectorStores.

Fix: after 2.2.3
Fix from $1,950 2025-04-09
Flowise CRITICAL 9.8
CVE-2025-26319EPSS 56%

FlowiseAI Flowise v2.2.6 was discovered to contain an arbitrary file upload vulnerability in /api/v1/attachments.

Patch available
Fix from $2,300 2025-03-04
Embed MEDIUM 6.1
CVE-2024-9148

Flowise < 2.1.1 suffers from a Stored Cross-Site vulnerability due to a lack of input sanitization in Flowise Chat Embed < 2.0.0.

Fix: 2.0.0 / 2.1.1+
Fix from $1,600 2024-09-25
Flowise HIGH 7.5
CVE-2024-8182EPSS 14%

An Unauthenticated Denial of Service (DoS) vulnerability exists in Flowise version 1.8.2 leading to a complete crash of the instance running a vulner…

Mitigation only
Fix from $1,950 2024-08-27
Flowise HIGH 8.1
CVE-2024-8181EPSS 45%

An Authentication Bypass vulnerability exists in Flowise version 1.8.2. This could allow a remote, unauthenticated attacker to access API endpoints a…

Mitigation only
Fix from $1,950 2024-08-27
Flowise MEDIUM 6.1
CVE-2024-37146

Flowise is a drag & drop user interface to build a customized large language model flow. In version 1.4.3 of Flowise, a reflected cross-site scriptin…

Fix: after 1.4.3
Fix from $1,600 2024-07-01
Flowise MEDIUM 6.1
CVE-2024-36423

Flowise is a drag & drop user interface to build a customized large language model flow. In version 1.4.3 of Flowise, a reflected cross-site scriptin…

Fix: after 1.4.3
Fix from $1,600 2024-07-01
Flowise MEDIUM 6.1
CVE-2024-37145

Flowise is a drag & drop user interface to build a customized large language model flow. In version 1.4.3 of Flowise, a reflected cross-site scriptin…

Fix: after 1.4.3
Fix from $1,600 2024-07-01
Flowise HIGH 7.5
CVE-2024-36420

Flowise is a drag & drop user interface to build a customized large language model flow. In version 1.4.3 of Flowise, the `/api/v1/openai-assistants-…

No fix yet
Fix from $1,950 2024-07-01
Flowise HIGH 7.5
CVE-2024-36421EPSS 8%

Flowise is a drag & drop user interface to build a customized large language model flow. In version 1.4.3 of Flowise, A CORS misconfiguration sets th…

No fix yet
Fix from $1,950 2024-07-01
Flowise MEDIUM 6.1
CVE-2024-36422

Flowise is a drag & drop user interface to build a customized large language model flow. In version 1.4.3 of Flowise, a reflected cross-site scriptin…

No fix yet
Fix from $1,600 2024-07-01
Flowise HIGH 7.6
CVE-2024-31621EPSS 60%

An issue in FlowiseAI Inc Flowise v.1.6.2 and before allows a remote attacker to execute arbitrary code via a crafted script to the api/v1 component.

Fix: after 1.6.5
Fix from $1,950 2024-04-29