CVE Tools

Flow

27 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Flow, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.

Flow CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Flow CVEs per month
MonthCVEs
2024-100
2024-111
2024-120
2025-010
2025-020
2025-030
2025-040
2025-052
2025-060
2025-070
2025-080
2025-090
2025-101
2025-110
2025-120
2026-011
2026-020
2026-032
2026-041
2026-051
2026-060
2026-071
2026-080
2026-090

Severity

How the 27 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • High727%
  • Medium1765%
  • Low28%

Latest CVEs

The 15 most recently published vulnerabilities affecting Flow.

  1. CVE-2026-57793WordPress Flow theme <= 1.8 - Local File Inclusion vulnerability7.5
  2. CVE-2026-7860Possible information disclosure of environment variables in Vaadin Build Plugins via Failed Frontend Build—
  3. CVE-2026-22683Windmill < 1.615.0 Operator Role Missing Authorization Checks RCE8.8
  4. CVE-2026-2742Unauthorized session creation via reserved framework path access5.3
  5. CVE-2026-2741Zip Slip Path Traversal on Node Unpack6.8
  6. CVE-2026-1126lwj flow SVG File FormResource.java uploadFile unrestricted upload6.3
  7. CVE-2025-11655Total.js Flow SVG File unrestricted upload4.7
  8. CVE-2025-20972Improper verification of intent by broadcast receiver in Samsung Flow prior to version 4.9.17.6 allows local attackers to modify Samsung Flow configuration.6.2
  9. CVE-2025-20971Improper input validation in Samsung Flow prior to version 4.9.17.6 allows local attackers to access data within Samsung Flow.5.5
  10. CVE-2024-49407Improper access control in Samsung Flow prior to version 4.9.15.7 allows physical attackers to access data across multiple user profiles.4.6
  11. CVE-2024-34600Improper verification of intent by broadcast receiver vulnerability in Samsung Flow prior to version 4.9.13.0 allows local attackers to copy image files to external storage.4.4
  12. CVE-2023-30094A stored cross-site scripting (XSS) vulnerability in TotalJS Flow v10 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the platform name field in the se...5.4
  13. CVE-2023-21444Improper cryptographic implementation in Samsung Flow for PC 4.9.14.0 allows adjacent attackers to decrypt encrypted messages or inject commands.7.5
  14. CVE-2023-21443Improper cryptographic implementation in Samsung Flow for Android prior to version 4.9.04 allows adjacent attackers to decrypt encrypted messages or inject commands.7.5
  15. CVE-2021-31412Possible route enumeration in production mode via RouteNotFoundError view in Vaadin 10, 11-14, and 15-195.3

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store