VendorsInfiniFlowragflowany version
Vulnerabilities

InfiniFlow RAGFlow any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

8CVEs
CVE-2024-12433
Remote Code Execution in infiniflow/ragflow
Published 2025-03-20 · Analyzed
9.8EPSS 0.017
CVE-2026-24770
RAGFlow Affected by Zip Slip Remote Code Execution (RCE) in MinerUParser
Published 2026-01-27 · Analyzed
9.8EPSS 0.014
CVE-2025-69286
RAGFlow has Predictable Token Generation Leading to Authentication Bypass Vulnerability
Published 2025-12-31 · Analyzed
9.8EPSS 0.008
CVE-2025-27135
RAGFlow SQL Injection vulnerability
Published 2025-02-25 · Analyzed
9.8EPSS 0.006
CVE-2025-48187
RAGFlow through 0.18.1 allows account takeover because it is possible to conduct successful brute-force attacks against email verification codes to perform arbitrary account registration, login, and password reset. Codes are six digits and there is no rate limiting.
Published 2025-05-17 · Analyzed
9.8EPSS 0.005
CVE-2025-68700
RAGFlow Remote Code Execution Vulnerability
Published 2025-12-31 · Analyzed
8.8EPSS 0.007
CVE-2026-28797
RAGFlow: Server-Side Template Injection (SSTI) leading to Remote Code Execution (RCE) in Agent "Text Processing" Component
Published 2026-04-03 · Analyzed
8.8EPSS 0.006
CVE-2025-25282
Potential Insecure Direct Object Reference (IDOR) vulnerability in ragflow
Published 2025-02-21 · Analyzed
8.1EPSS 0.005