Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 6.5
CVE-2025-57164
Flowise through v3.0.4 is vulnerable to remote code execution via unsanitized evaluation of user input in the "Supabase RPC Filter" field.
Flowise
No fix yet
CRITICAL 9.9
CVE-2025-34267EPSS 6%
Flowise v3.0.1 < 3.0.8 and all versions after with 'ALLOW_BUILTIN_DEP' enabled contain an authenticated remote code execution vulnerability and node …
Flowise
3.0.8+
CRITICAL 9.9
CVE-2025-61913EPSS 12%
Flowise is a drag & drop user interface to build a customized large language model flow. In versions prior to 3.0.8, WriteFileTool and ReadFileTool i…
Flowise
3.0.8+
HIGH 8.8
CVE-2025-61687EPSS 10%
Flowise is a drag & drop user interface to build a customized large language model flow. A file upload vulnerability in version 3.0.7 of FlowiseAI al…
Flowise
No fix yet
MEDIUM 6.1
CVE-2025-29192
Flowise before 3.0.5 allows XSS via a FORM element and an INPUT element when an admin views the chat log.
Flowise
3.0.5+
MEDIUM 6.1
CVE-2025-50538EPSS 13%
Flowise before 3.0.5 allows XSS via an IFRAME element when an admin views the chat log.
Flowise
3.0.5+
CRITICAL 10.0
CVE-2025-59528EPSS 90%
Flowise is a drag & drop user interface to build a customized large language model flow. In version 3.0.5, Flowise is vulnerable to remote code execu…
Flowise
Mitigation only
HIGH 7.5
CVE-2025-59527
Flowise is a drag & drop user interface to build a customized large language model flow. In version 3.0.5, a Server-Side Request Forgery (SSRF) vulne…
Flowise
No fix yet
CRITICAL 9.8
CVE-2025-58434EPSS 50%
Flowise is a drag & drop user interface to build a customized large language model flow. In version 3.0.5 and earlier, the `forgot-password` endpoint…
Flowise
3.0.6+
CRITICAL 9.8
CVE-2025-8943EPSS 72%
The Custom MCPs feature is designed to execute OS commands, for instance, using tools like `npx` to spin up local MCP Servers. However, Flowise's inh…
Flowise
3.0.1+
HIGH 7.6
CVE-2025-29189
Flowise <= 2.2.3 is vulnerable to SQL Injection. via tableName parameter at Postgres_VectorStores.
Flowise
after 2.2.3
CRITICAL 9.8
CVE-2025-26319EPSS 56%
FlowiseAI Flowise v2.2.6 was discovered to contain an arbitrary file upload vulnerability in /api/v1/attachments.
Flowise
Patch available
MEDIUM 6.1
CVE-2024-9148
Flowise < 2.1.1 suffers from a Stored Cross-Site vulnerability due to a lack of input sanitization in Flowise Chat Embed < 2.0.0.
Embed
2.0.0 / 2.1.1+
HIGH 7.5
CVE-2024-8182EPSS 14%
An Unauthenticated Denial of Service (DoS) vulnerability exists in Flowise version 1.8.2 leading to a complete crash of the instance running a vulner…
Flowise
Mitigation only
HIGH 8.1
CVE-2024-8181EPSS 45%
An Authentication Bypass vulnerability exists in Flowise version 1.8.2. This could allow a remote, unauthenticated attacker to access API endpoints a…
Flowise
Mitigation only
MEDIUM 6.1
CVE-2024-37146
Flowise is a drag & drop user interface to build a customized large language model flow. In version 1.4.3 of Flowise, a reflected cross-site scriptin…
Flowise
after 1.4.3
MEDIUM 6.1
CVE-2024-36423
Flowise is a drag & drop user interface to build a customized large language model flow. In version 1.4.3 of Flowise, a reflected cross-site scriptin…
Flowise
after 1.4.3
MEDIUM 6.1
CVE-2024-37145
Flowise is a drag & drop user interface to build a customized large language model flow. In version 1.4.3 of Flowise, a reflected cross-site scriptin…
Flowise
after 1.4.3
HIGH 7.5
CVE-2024-36420
Flowise is a drag & drop user interface to build a customized large language model flow. In version 1.4.3 of Flowise, the `/api/v1/openai-assistants-…
Flowise
No fix yet
HIGH 7.5
CVE-2024-36421EPSS 8%
Flowise is a drag & drop user interface to build a customized large language model flow. In version 1.4.3 of Flowise, A CORS misconfiguration sets th…
Flowise
No fix yet
MEDIUM 6.1
CVE-2024-36422
Flowise is a drag & drop user interface to build a customized large language model flow. In version 1.4.3 of Flowise, a reflected cross-site scriptin…
Flowise
No fix yet
HIGH 7.6
CVE-2024-31621EPSS 60%
An issue in FlowiseAI Inc Flowise v.1.6.2 and before allows a remote attacker to execute arbitrary code via a crafted script to the api/v1 component.
Flowise
after 1.6.5