Vulnerability index

Browse CVEs

82 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Flowise CRITICAL 9.8
CVE-2026-56271

Flowise before 3.1.0 (affected versions 3.0.13 and earlier) uses weak hardcoded default JWT secrets ('auth_token', 'refresh_token') and default audie…

Fix: 3.1.0+
Fix from $2,300 2026-07-12
Flowise CRITICAL 9.1
CVE-2026-56278

Flowise before 3.1.0 (affected versions 3.0.13 and earlier) uses a weak hardcoded default secret ('flowise') for the express-session middleware when …

Fix: 3.1.0+
Fix from $2,300 2026-06-30
Flowise MEDIUM 6.5
CVE-2026-56277

Flowise before 3.1.2 sets Access-Control-Allow-Origin to a hardcoded wildcard (*) on its text-to-speech (TTS) generation endpoint (packages/server/sr…

Fix: 3.1.2+
Fix from $1,600 2026-06-30
Flowise MEDIUM 5.0
CVE-2026-58057

Flowise before 3.1.3 validates Custom MCP stdio environment variables against a denylist using a case-sensitive comparison, so on Windows, where envi…

Fix: 3.1.3+
Fix from $1,600 2026-06-28
Flowise CRITICAL 9.8
CVE-2025-71333

Flowise through 2.2.4 contains an unauthenticated arbitrary file upload vulnerability in the /api/v1/attachments endpoint when storageType is set to …

Fix: after 2.2.4
Fix from $2,300 2026-06-25
Flowise CRITICAL 9.8
CVE-2025-71334

Flowise before 3.0.6 (affected versions 2.2.8 and earlier) contains an arbitrary file access vulnerability due to missing validation that the chatflo…

Fix: 3.0.6+
Fix from $2,300 2026-06-25
Flowise CRITICAL 9.8
CVE-2025-71336

Flowise before 3.0.6 (affected versions 2.2.7-patch.1 and earlier) contains an unsandboxed remote code execution vulnerability in the Custom MCP feat…

Fix: 3.0.6+
Fix from $2,300 2026-06-25
Flowise CRITICAL 9.8
CVE-2025-71338

Flowise contains a path traversal vulnerability in the /api/v1/document-store/loader/process endpoint that allows unauthenticated attackers to write …

Fix: after 3.1.3
Fix from $2,300 2026-06-25
Flowise HIGH 8.1
CVE-2025-71335

Flowise before 3.0.10 (affected versions 3.0.7 and earlier) fails to invalidate existing sessions and session tokens after a user changes their passw…

Fix: 3.0.10+
Fix from $1,950 2026-06-25
Flowise CRITICAL 9.1
CVE-2025-71327

Flowise contains an authentication bypass vulnerability in the unprotected /api/v1/account/register endpoint that allows unauthenticated attackers to…

No fix yet
Fix from $2,300 2026-06-25
Flowise HIGH 8.8
CVE-2025-71328

Flowise before 3.0.10 contains an unverified password change vulnerability. An authenticated user can change their account password through the accou…

Fix: 3.0.10+
Fix from $1,950 2026-06-25
Flowise HIGH 7.5
CVE-2025-71324

Flowise before 3.0.6 contains an arbitrary file read vulnerability in the chatId parameter of the /api/v1/get-upload-file and /api/v1/openai-assistan…

Fix: 3.0.6+
Fix from $1,950 2026-06-25
Flowise HIGH 7.5
CVE-2026-56270

Flowise before 3.1.0 (versions 3.0.13 and earlier) contains a missing authentication vulnerability in the /api/v1/loginmethod endpoint that allows un…

Fix: 3.1.0+
Fix from $1,950 2026-06-24
Flowise HIGH 8.8
CVE-2025-71332

Flowise through 2.2.7 contains a SQL injection vulnerability in the importChatflows API. Due to insufficient validation of the chatflow.id value, an …

Fix: after 2.2.7
Fix from $1,950 2026-06-24
Flowise CRITICAL 9.9
CVE-2026-56274

Flowise before 3.1.2 contains multiple OS command injection vulnerabilities in the Custom MCP Server feature due to incomplete command-flag validatio…

Fix: 3.1.2+
Fix from $2,300 2026-06-23
Flowise HIGH 7.1
CVE-2026-56275

Flowise before 3.1.0 contains a server-side request forgery vulnerability in the Execute Flow node that allows attackers to bypass security validatio…

Fix: 3.1.0+
Fix from $1,950 2026-06-23
Flowise HIGH 8.3
CVE-2025-71337

Flowise before 3.0.10 (affected versions 3.0.7 and earlier) contains an unverified email change vulnerability. An authenticated user can change the a…

Fix: after 3.0.7
Fix from $1,950 2026-06-23
Flowise HIGH 7.7
CVE-2026-56268

Flowise before 3.1.2 contains an information disclosure vulnerability in the /api/v1/chatflows/apikey/:apikey endpoint. When the keyonly query parame…

Fix: 3.1.2+
Fix from $1,950 2026-06-22
Flowise MEDIUM 6.1
CVE-2025-71331

Flowise before 3.0.8 contains a cross-site scripting (XSS) vulnerability caused by insufficient input filtering in chat messages and custom agent fun…

Fix: 3.0.8+
Fix from $1,600 2026-06-20
Flowise HIGH 8.8
CVE-2026-46477

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, dataset create and update mass-assig…

Fix: 3.1.2+
Fix from $1,950 2026-06-08
Flowise HIGH 8.8
CVE-2026-46478

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, DatasetRow create and update mass-as…

Fix: 3.1.2+
Fix from $1,950 2026-06-08
Flowise HIGH 8.8
CVE-2026-46479

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, evaluation create and update mass-as…

Fix: 3.1.2+
Fix from $1,950 2026-06-08
Flowise HIGH 8.8
CVE-2026-46480

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, evaluator create and update mass-ass…

Fix: 3.1.2+
Fix from $1,950 2026-06-08
Flowise CRITICAL 9.9
CVE-2026-46442

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, POST /api/v1/node-custom-function la…

Fix: 3.1.2+
Fix from $2,300 2026-06-08
Flowise CRITICAL 9.6
CVE-2026-46441

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass assignment vulnerability exis…

Fix: 3.1.2+
Fix from $2,300 2026-06-08
Flowise CRITICAL 9.1
CVE-2026-46440

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, the checkBasicAuth endpoint validate…

Fix: 3.1.2+
Fix from $2,300 2026-06-08
Flowise HIGH 8.8
CVE-2026-46444

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, all CRUD endpoints for OpenAI Assist…

Fix: 3.1.2+
Fix from $1,950 2026-06-08
Flowise HIGH 8.8
CVE-2026-46475

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, assistant create and update mass-ass…

Fix: 3.1.2+
Fix from $1,950 2026-06-08
Flowise HIGH 8.8
CVE-2026-46476

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, CustomTemplate create and update mas…

Fix: 3.1.2+
Fix from $1,950 2026-06-08
Flowise MEDIUM 6.5
CVE-2026-46443

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, when credentials are fetched with a …

Fix: 3.1.2+
Fix from $1,600 2026-06-08