Flowise
23 CVEs tracked since 2026. Since Jun 2026, none of them reached CISA KEV.
Flowise CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2026-06 | 23 | 0 |
Products
The products that kept showing up in Flowise's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Flowise.
- CVE-2026-56271Flowise - Weak Default JWT Secrets in Authentication Middleware9.8
- CVE-2026-56273Flowise - Path Traversal in Vector Store basePath Parameter6.5
- CVE-2026-56278Flowise - Session Hijacking via Weak Default Express Session Secret9.1
- CVE-2026-56277Flowise - Hardcoded CORS Wildcard in TTS Endpoint6.5
- CVE-2026-58057Flowise - Custom MCP Environment Variable Denylist Bypass via Case Sensitivity5.0
- CVE-2025-71338Flowise through 2.2.7 - Arbitrary File Write to Remote Code Execution via document-store API10.0
- CVE-2025-71336Flowise - Unsandboxed Remote Code Execution via Custom MCP9.8
- CVE-2025-71335Flowise - Session Invalidation Failure After Password Change8.1
- CVE-2025-71334Flowise - Arbitrary File Access via Missing Chat Flow ID Validation9.8
- CVE-2025-71333Flowise - Arbitrary File Upload via Unauthenticated /api/v1/attachments Endpoint9.8
- CVE-2025-71328Flowise - Unverified Password Change via Account Settings8.3
- CVE-2025-71327Flowise - Authentication Bypass via Unprotected Registration Endpoint9.1
- CVE-2025-71324Flowise - Arbitrary File Read via chatId Parameter7.5
- CVE-2026-56272Flowise - Insufficient Password Salt Rounds in Bcrypt Hashing4.1
- CVE-2026-56270Flowise - Unauthenticated OAuth Secrets Disclosure via /api/v1/loginmethod Endpoint7.5
The record
- Peak rank
- #43 in Jun 2026
- Busiest month shown
- Jun 2026, 23 CVEs
- Months with a KEV entry
- 0 since Jun 2026
- Monthly snapshots
- 1 since 2026