VendorsFlowiseAIflowiseall versions
Vulnerabilities

FlowiseAI Flowise

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

128CVEs
CVE-2024-37146
GHSL-2023-248: Flowise xss in /api/v1/credentials/id
Published 2024-07-01 · Modified
6.1EPSS 0.004
CVE-2024-36423
GHSL-2023-246: Flowise xss in /api/v1/public-chatflows/id
Published 2024-07-01 · Modified
6.1EPSS 0.004
CVE-2025-71331
Flowise - Cross-Site Scripting in Chat Messages and Agent Workflows
Published 2026-06-20 · Analyzed
6.1EPSS 0.003
CVE-2026-56272
Flowise - Insufficient Password Salt Rounds in Bcrypt Hashing
Published 2026-06-24 · Analyzed
5.6EPSS 0.001
CVE-2026-8027
FlowiseAI Flowise User Controller authorization
Published 2026-05-06 · Analyzed
5.3EPSS 0.004
CVE-2026-58057
Flowise - Custom MCP Environment Variable Denylist Bypass via Case Sensitivity
Published 2026-06-28 · Analyzed
5.01 PoCEPSS 0.016
CVE-2026-56269
Flowise - Weak Default Token Hash Secret in JWT Token Encryption
Published 2026-06-24 · Analyzed
4.6EPSS 0.001
CVE-2026-8028
FlowiseAI Flowise Endpoint account.service.ts verify information disclosure
Published 2026-05-06 · Analyzed
3.7EPSS 0.005
← Prev4 / 4