CVE Tools

Ragflow

20 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Ragflow. Use it to gauge the current risk picture and drill into individual advisories.

Ragflow CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Ragflow CVEs per month
MonthCVEs
2024-101
2024-110
2024-121
2025-010
2025-022
2025-036
2025-040
2025-051
2025-060
2025-071
2025-080
2025-090
2025-100
2025-110
2025-122
2026-011
2026-020
2026-030
2026-041
2026-051
2026-060
2026-071
2026-081
2026-091

Severity

How the 20 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical735%
  • High735%
  • Medium630%

Latest CVEs

The 15 most recently published vulnerabilities affecting Ragflow.

  1. CVE-2026-93013RAGFlow through 0.27.2 Tenant Import Endpoints Path Traversal4.3
  2. CVE-2026-75898RAGFlow < 0.26.3 - Server-Side Request Forgery via Agent Invoke Component8.5
  3. CVE-2026-58579RAGFlow < 0.26.3 - Stored Cross-Site Scripting via Agent Pipeline Node Name5.4
  4. CVE-2026-45312RAGFlow: Server-Side Template Injection in Prompt Generator leads to Remote Code Execution9.9
  5. CVE-2026-28797RAGFlow: Server-Side Template Injection (SSTI) leading to Remote Code Execution (RCE) in Agent "Text Processing" Component8.8
  6. CVE-2026-24770RAGFlow Affected by Zip Slip Remote Code Execution (RCE) in MinerUParser9.8
  7. CVE-2025-69286RAGFlow has Predictable Token Generation Leading to Authentication Bypass Vulnerability9.8
  8. CVE-2025-68700RAGFlow Remote Code Execution Vulnerability8.8
  9. CVE-2025-51462Stored Cross-site Scripting (XSS) vulnerability in api.apps.dialog_app.set_dialog in RAGFlow 0.17.2 allows remote attackers to execute arbitrary JavaScript via crafted input to the assistant greeti...6.1
  10. CVE-2025-48187RAGFlow through 0.18.1 allows account takeover because it is possible to conduct successful brute-force attacks against email verification codes to perform arbitrary account registration, login, an...9.1
  11. CVE-2024-12779SSRF in infiniflow/ragflow7.5
  12. CVE-2024-12869Improper Authentication in infiniflow/ragflow4.3
  13. CVE-2024-12871Stored Cross-site Scripting (XSS) in infiniflow/ragflow5.4
  14. CVE-2024-12450RCE, Full Read SSRF, and Arbitrary File Read in infiniflow/ragflow9.8
  15. CVE-2024-12433Remote Code Execution in infiniflow/ragflow9.8

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store