Flowiseai
119 CVEs tracked since 2024. Since Jul 2024, none of them reached CISA KEV.
Flowiseai CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2024-07 | 6 | 0 |
| 2024-08 | null or fewer | |
| 2024-09 | null or fewer | |
| 2024-10 | null or fewer | |
| 2024-11 | null or fewer | |
| 2024-12 | null or fewer | |
| 2025-01 | null or fewer | |
| 2025-02 | null or fewer | |
| 2025-03 | null or fewer | |
| 2025-04 | null or fewer | |
| 2025-05 | null or fewer | |
| 2025-06 | null or fewer | |
| 2025-07 | null or fewer | |
| 2025-08 | null or fewer | |
| 2025-09 | 4 | 0 |
| 2025-10 | 6 | 0 |
| 2025-11 | null or fewer | |
| 2025-12 | null or fewer | |
| 2026-01 | null or fewer | |
| 2026-02 | null or fewer | |
| 2026-03 | null or fewer | |
| 2026-04 | 19 | 0 |
| 2026-05 | null or fewer | |
| 2026-06 | 32 | 0 |
| 2026-07 | null or fewer | |
| 2026-08 | 37 | 0 |
| 2026-09 | 15 | 0 |
Products
The products that kept showing up in Flowiseai's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Flowiseai.
- CVE-2026-100610Flowise through 3.1.4 Missing Authorization via upsert-history7.5
- CVE-2026-100609Flowise through 3.1.4 Insecure Direct Object Reference via Credential6.8
- CVE-2026-100608Flowise through 3.1.4 Authorization Bypass via BullMQ Dashboard8.3
- CVE-2026-100607Flowise through 3.1.4 Authentication Bypass via Email-Only SSO7.7
- CVE-2026-100606Flowise through 3.1.4 Authentication Bypass via SSO Email Match7.7
- CVE-2026-100605Flowise through 3.1.4 Missing Authorization via Chat Message Routes7.1
- CVE-2026-91938Flowise before 3.1.4 Server-Side Request Forgery via document loaders7.1
- CVE-2026-91937Flowise before 3.1.4 NoSQL Injection via sessionId7.5
- CVE-2026-91936Flowise before 3.1.4 Script Injection via Docker Workflows6.8
- CVE-2026-91935Flowise before 3.1.4 SSRF and API Key Exfiltration via Chat Model Nodes8.3
- CVE-2026-91934Flowise before 3.1.4 Remote Code Execution via SQL Database Chain8.8
- CVE-2026-91933Flowise before 3.1.4 Authorization Bypass via openai-realtime7.1
- CVE-2026-91932Flowise before 3.1.4 Remote Code Execution via cwd Parameter8.5
- CVE-2026-91931Flowise before 3.1.4 Remote Code Execution via Custom MCP npx8.5
- CVE-2026-91930Flowise before 3.1.4 Cross-Tenant Organization Admin Takeover7.5
The record
- Peak rank
- #27 in Jun 2026
- Busiest month shown
- Aug 2026, 37 CVEs
- Months with a KEV entry
- 0 since Jul 2024
- Monthly snapshots
- 7 since 2024