Flowise
207 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Flowise, a product in the ai ml space. Use it to gauge the current risk picture and drill into individual advisories.
Flowise CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 1 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 3 |
| 2025-04 | 2 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 2 |
| 2025-09 | 7 |
| 2025-10 | 8 |
| 2025-11 | 2 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 8 |
| 2026-04 | 43 |
| 2026-05 | 19 |
| 2026-06 | 38 |
| 2026-07 | 2 |
| 2026-08 | 41 |
| 2026-09 | 21 |
Severity
How the 207 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical42
- High78
- Medium26
- Low2
Latest CVEs
The 15 most recently published vulnerabilities affecting Flowise.
- CVE-2026-100610Flowise through 3.1.4 Missing Authorization via upsert-history7.5
- CVE-2026-100609Flowise through 3.1.4 Insecure Direct Object Reference via Credential6.8
- CVE-2026-100608Flowise through 3.1.4 Authorization Bypass via BullMQ Dashboard8.3
- CVE-2026-100607Flowise through 3.1.4 Authentication Bypass via Email-Only SSO7.7
- CVE-2026-100606Flowise through 3.1.4 Authentication Bypass via SSO Email Match7.7
- CVE-2026-100605Flowise through 3.1.4 Missing Authorization via Chat Message Routes7.1
- CVE-2026-91938Flowise before 3.1.4 Server-Side Request Forgery via document loaders7.1
- CVE-2026-91937Flowise before 3.1.4 NoSQL Injection via sessionId7.5
- CVE-2026-91936Flowise before 3.1.4 Script Injection via Docker Workflows6.8
- CVE-2026-91935Flowise before 3.1.4 SSRF and API Key Exfiltration via Chat Model Nodes8.3
- CVE-2026-91934Flowise before 3.1.4 Remote Code Execution via SQL Database Chain8.8
- CVE-2026-91933Flowise before 3.1.4 Authorization Bypass via openai-realtime7.1
- CVE-2026-91932Flowise before 3.1.4 Remote Code Execution via cwd Parameter8.5
- CVE-2026-91931Flowise before 3.1.4 Remote Code Execution via Custom MCP npx8.5
- CVE-2026-91930Flowise before 3.1.4 Cross-Tenant Organization Admin Takeover7.5
Product grouping is registry-driven, with AI assist and human review. How it works