Infiniflow
7 CVEs tracked since 2025. Since Mar 2025, none of them reached CISA KEV.
Infiniflow CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2025-03 | 7 | 0 |
Products
The products that kept showing up in Infiniflow's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Infiniflow.
- CVE-2026-93013RAGFlow through 0.27.2 Tenant Import Endpoints Path Traversal4.3
- CVE-2026-75898RAGFlow < 0.26.3 - Server-Side Request Forgery via Agent Invoke Component8.5
- CVE-2026-58579RAGFlow < 0.26.3 - Stored Cross-Site Scripting via Agent Pipeline Node Name5.4
- CVE-2026-45312RAGFlow: Server-Side Template Injection in Prompt Generator leads to Remote Code Execution9.9
- CVE-2026-28797RAGFlow: Server-Side Template Injection (SSTI) leading to Remote Code Execution (RCE) in Agent "Text Processing" Component8.8
- CVE-2026-24770RAGFlow Affected by Zip Slip Remote Code Execution (RCE) in MinerUParser9.8
- CVE-2025-69286RAGFlow has Predictable Token Generation Leading to Authentication Bypass Vulnerability9.8
- CVE-2025-68700RAGFlow Remote Code Execution Vulnerability8.8
- CVE-2025-51462Stored Cross-site Scripting (XSS) vulnerability in api.apps.dialog_app.set_dialog in RAGFlow 0.17.2 allows remote attackers to execute arbitrary JavaScript via crafted input to the assistant greeti...6.1
- CVE-2025-48187RAGFlow through 0.18.1 allows account takeover because it is possible to conduct successful brute-force attacks against email verification codes to perform arbitrary account registration, login, an...9.1
- CVE-2024-12779SSRF in infiniflow/ragflow7.5
- CVE-2024-12869Improper Authentication in infiniflow/ragflow4.3
- CVE-2024-12871Stored Cross-site Scripting (XSS) in infiniflow/ragflow5.4
- CVE-2024-12450RCE, Full Read SSRF, and Arbitrary File Read in infiniflow/ragflow9.8
- CVE-2024-12870Stored Cross-site Scripting (XSS) in infiniflow/ragflow5.4
The record
- Peak rank
- #133 in Mar 2025
- Busiest month shown
- Mar 2025, 7 CVEs
- Months with a KEV entry
- 0 since Mar 2025
- Monthly snapshots
- 1 since 2025