Known vulnerabilities in Flowise

Vendor: FlowiseAI
Software: Flowise
Software CPE: cpe:2.3:a:flowiseai:flowise:*:*:*:*:*:*:*:*
Total vulnerabilities: 133
Public exploits: 6
Known exploited (KEV): 4
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Flowise Flowise is affected by 133 known vulnerabilities: 20 high, 77 medium, 36 low Critical High Medium Low

Vulnerabilities (133)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU146556 - Cleartext Storage of Sensitive Information
CWE-312 Low
No
No
3.1.4 01.09.2026 SB2026083134
#VU146557 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CWE-78 Medium
No
No
3.1.4 01.09.2026 SB2026083134
#VU146558 - Improper Control of Generation of Code ('Code Injection')
CWE-94 Low
No
No
3.1.4 01.09.2026 SB2026083134
#VU146559 - Improper Control of Generation of Code ('Code Injection')
CWE-94 Low
No
No
3.1.4 01.09.2026 SB2026083134
#VU146555 - Server-Side Request Forgery (SSRF)
CWE-918 Low
No
No
3.1.4 01.09.2026 SB2026083134
#VU146554 - Improper Neutralization of Special Elements in Data Query Logic
CWE-943 Medium
No
No
3.1.4 01.09.2026 SB2026083134
#VU146553 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CWE-78 Low
No
No
3.1.4 01.09.2026 SB2026083134
#VU146552 - Server-Side Request Forgery (SSRF)
CWE-918 Low
No
No
3.1.4 01.09.2026 SB2026083134
#VU146550 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CWE-22 Medium
No
No
3.1.4 01.09.2026 SB2026083134
#VU146551 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CWE-22 Low
No
No
3.1.4 01.09.2026 SB2026083134
#VU146549 - Authorization Bypass Through User-Controlled Key
CWE-639 Medium
No
No
3.1.4 01.09.2026 SB2026083134
#VU146548 - Improper input validation
CWE-20 Medium
No
No
3.1.4 01.09.2026 SB2026083134
#VU146547 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CWE-78 Medium
No
No
3.1.4 01.09.2026 SB2026083134
#VU146546 - Authorization Bypass Through User-Controlled Key
CWE-639 Medium
No
No
3.1.4 01.09.2026 SB2026083134
#VU146337 - Missing Authorization
CVE-2026-90535
CWE-862 Medium
No
No
3.1.4 31.08.2026 SB2026083134
#VU146336 - Authorization Bypass Through User-Controlled Key
CVE-2026-90534
CWE-639 Medium
No
No
3.1.4 31.08.2026 SB2026083134
#VU146335 - Missing Authorization
CVE-2026-90533
CWE-862 Low
No
No
3.1.4 31.08.2026 SB2026083134
#VU139753 - Exposure of sensitive information to an unauthorized actor
CVE-2026-73604
CWE-200 Low
No
No
3.1.3 27.07.2026 SB20260727343
#VU139752 - Missing Authorization
CVE-2026-73603
CWE-862 Medium
No
No
- 27.07.2026 SB20260727378
#VU139751 - Authorization Bypass Through User-Controlled Key
CVE-2026-73488
CWE-639 Low
No
No
3.1.3 27.07.2026 SB20260727343


Showing elements 1 - 20 out of 133