Flowise-ai
4 CVEs tracked since 2025. Since Sep 2025, none of them reached CISA KEV.
Flowise-ai CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2025-09 | 4 | 0 |
Products
The products that kept showing up in Flowise-ai's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 6 most recently published vulnerabilities affecting Flowise-ai.
- CVE-2025-59528Flowise has Remote Code Execution vulnerability10.0
- CVE-2025-59527FlowiseAI/Flowise has Server-Side Request Forgery (SSRF) vulnerability7.5
- CVE-2025-59434Critical Multi-Tenant Variable Disclosure in Flowise Cloud via Custom JavaScript Function9.6
- CVE-2025-58434Flowise Cloud and Local Deployments have Unauthenticated Password Reset Token Disclosure that Leads to Account Takeover9.8
- CVE-2025-8943Unsupervised OS command execution leads to remote code execution by unauthenticated network attackers9.8
- CVE-2025-26319FlowiseAI Flowise v2.2.6 was discovered to contain an arbitrary file upload vulnerability in /api/v1/attachments.9.8
The record
- Peak rank
- #178 in Sep 2025
- Busiest month shown
- Sep 2025, 4 CVEs
- Months with a KEV entry
- 0 since Sep 2025
- Monthly snapshots
- 1 since 2025