| CVE-2025-71338 | 10 | critical | flowiseai / flowise | Flowise contains a path traversal vulnerability in the /api/v1/document-store/loader/process endpoint that allows | 72d ago |
| CVE-2026-73602 | 9.9 | critical | flowiseai / flowise | Flowise before 3.1.3 contains a sandbox escape vulnerability in the vm2 JavaScript sandbox that allows authenticat | 23d ago |
| CVE-2026-56274 | 9.9 | critical | flowiseai / flowise | Flowise before 3.1.2 contains multiple OS command injection vulnerabilities in the Custom MCP Server feature due t | 74d ago |
| CVE-2026-46442 | 9.9 | critical | flowiseai / flowise | Flowise is a drag & drop user interface to build a customized large language model flow. | 89d ago |
| CVE-2026-73487 | 9.8 | critical | flowiseai / flowise | Flowise before 3.1.3 contains a regex-based Python code validator bypass in CSV and Airtable Agent nodes that allo | 23d ago |
| CVE-2026-56271 | 9.8 | critical | flowiseai / flowise | Flowise before 3.1.0 (affected versions 3.0.13 and earlier) uses weak hardcoded default JWT secrets ('auth_token', | 55d ago |
| CVE-2025-71336 | 9.8 | critical | flowiseai / flowise | Flowise before 3.0.6 (affected versions 2.2.7-patch.1 and earlier) contains an unsandboxed remote code execution v | 72d ago |
| CVE-2025-71334 | 9.8 | critical | flowiseai / flowise | Flowise before 3.0.6 (affected versions 2.2.8 and earlier) contains an arbitrary file access vulnerability due to | 72d ago |
| CVE-2025-71333 | 9.8 | critical | flowiseai / flowise | Flowise through 2.2.4 contains an unauthenticated arbitrary file upload vulnerability in the /api/v1/attachments e | 72d ago |
| CVE-2026-43995 | 9.8 | critical | flowiseai / flowise | Flowise is a drag & drop user interface to build a customized large language model flow. | 117d ago |
| CVE-2026-46441 | 9.6 | critical | flowiseai / flowise | Flowise is a drag & drop user interface to build a customized large language model flow. | 89d ago |
| CVE-2026-42861 | 9.6 | critical | flowiseai / flowise | Flowise is a drag & drop user interface to build a customized large language model flow. | 89d ago |
| CVE-2026-56278 | 9.1 | critical | flowiseai / flowise | Flowise before 3.1.0 (affected versions 3.0.13 and earlier) uses a weak hardcoded default secret ('flowise') for t | 67d ago |
| CVE-2025-71327 | 9.1 | critical | flowiseai / flowise | Flowise contains an authentication bypass vulnerability in the unprotected /api/v1/account/register endpoint that | 72d ago |
| CVE-2026-46440 | 9.1 | critical | flowiseai / flowise | Flowise is a drag & drop user interface to build a customized large language model flow. | 89d ago |
| CVE-2026-73601 | 8.8 | high | flowiseai / flowise | Flowise versions before 3.1.3 contain a remote code execution vulnerability in the Custom MCP node when CUSTOM_MCP | 23d ago |
| CVE-2026-73486 | 8.8 | high | flowiseai / flowise | Flowise before 3.1.3 contains a code injection vulnerability in the CSV Agent node's customReadCSV parameter that | 23d ago |
| CVE-2026-73485 | 8.8 | high | flowiseai / flowise | Flowise before 3.1.3 contains a code injection vulnerability in the Airtable Agent node that allows unauthenticate | 23d ago |
| CVE-2026-73483 | 8.8 | high | flowiseai / flowise | Flowise (packages flowise and flowise-components) in versions <= 3.1.2 contain a sandbox escape in the vm2/@flowis | 23d ago |
| CVE-2026-46480 | 8.8 | high | flowiseai / flowise | Flowise is a drag & drop user interface to build a customized large language model flow. | 89d ago |
| CVE-2026-46479 | 8.8 | high | flowiseai / flowise | Flowise is a drag & drop user interface to build a customized large language model flow. | 89d ago |
| CVE-2026-46478 | 8.8 | high | flowiseai / flowise | Flowise is a drag & drop user interface to build a customized large language model flow. | 89d ago |
| CVE-2026-46477 | 8.8 | high | flowiseai / flowise | Flowise is a drag & drop user interface to build a customized large language model flow. | 89d ago |
| CVE-2026-46476 | 8.8 | high | flowiseai / flowise | Flowise is a drag & drop user interface to build a customized large language model flow. | 89d ago |
| CVE-2026-46475 | 8.8 | high | flowiseai / flowise | Flowise is a drag & drop user interface to build a customized large language model flow. | 89d ago |
| CVE-2026-46444 | 8.8 | high | flowiseai / flowise | Flowise is a drag & drop user interface to build a customized large language model flow. | 89d ago |
| CVE-2025-71328 | 8.3 | high | flowiseai / flowise | Flowise before 3.0.10 contains an unverified password change vulnerability. | 72d ago |
| CVE-2025-71337 | 8.3 | high | flowiseai / flowise | Flowise before 3.0.10 (affected versions 3.0.7 and earlier) contains an unverified email change vulnerability. | 74d ago |
| CVE-2026-73484 | 8.1 | high | flowiseai / flowise | Flowise before 3.1.3 contains a sandbox escape vulnerability in pythonCodeValidator.ts that fails to block native | 23d ago |
| CVE-2025-71335 | 8.1 | high | flowiseai / flowise | Flowise before 3.0.10 (affected versions 3.0.7 and earlier) fails to invalidate existing sessions and session toke | 72d ago |
| CVE-2026-42863 | 8.1 | high | flowiseai / flowise | Flowise is a drag & drop user interface to build a customized large language model flow. | 89d ago |
| CVE-2026-67620 | 7.7 | high | flowiseai / flowise | Flowise through 3.1.4 contains a server-side request forgery vulnerability in the SSRF guard implemented in httpSe | 28d ago |
| CVE-2026-56268 | 7.7 | high | flowiseai / flowise | Flowise before 3.1.2 contains an information disclosure vulnerability in the /api/v1/chatflows/apikey/:apikey endp | 75d ago |
| CVE-2026-71962 | 7.5 | high | flowiseai / flowise | Flowise versions 2.2.4 through 3.1.4 contain a missing authorization vulnerability in the POST /api/v1/openai-assi | 26d ago |
| CVE-2025-71324 | 7.5 | high | flowiseai / flowise | Flowise before 3.0.6 contains an arbitrary file read vulnerability in the chatId parameter of the /api/v1/get-uplo | 72d ago |
| CVE-2026-56270 | 7.5 | high | flowiseai / flowise | Flowise before 3.1.0 (versions 3.0.13 and earlier) contains a missing authentication vulnerability in the /api/v1/ | 73d ago |
| CVE-2026-56275 | 7.1 | high | flowiseai / flowise | Flowise before 3.1.0 contains a server-side request forgery vulnerability in the Execute Flow node that allows att | 74d ago |