Known vulnerabilities in Flask
Vendor:
The Pallets Projects
Software:
Flask
Software CPE:
cpe:2.3:a:palletsprojects:flask:*:*:*:*:*:*:*:*
Website:
https://palletsprojects.com/
Total vulnerabilities:
5
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
8.8
Breakdown by Severity Chart
3.1.3
3.1.2
3.1.1
3.1.0
3.0.3
3.0.2
3.0.1
3.0.0
2.3.3
2.2.5
2.3.2
2.3.1
2.3.0
2.2.4
2.2.3
2.2.2
2.2.1
2.2.0
2.1.3
2.1.2
2.1.1
2.1.0
2.0.3
2.0.2
2.0.1
1.1.4
1.1.3
2.0.0
1.1.2
0.12.5
1.1.1
1.1.0
1.0.4
1.0.3
1.0.2
1.0.1
1.0
0.12.4
0.12.3
0.12.2
0.12.1
0.12
0.11.1
0.11
0.10.1
0.10
0.9
0.8.1
0.8
0.7.2
0.7.1
0.7
0.6.1
0.6
0.5
0.4
0.3.1
0.3
0.2
0.1
Vulnerabilities (5)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU124872 - Use of Cache Containing Sensitive Information CVE-2026-27205 |
CWE-524 | Medium | 3.1.3 | 06.04.2026 |
SB2026040613 SB2026040615 SB2026040617 and 14 more |
||
| #VU109059 - Cryptographic Issues CVE-2025-47278 |
CWE-310 | Low | 3.1.1 | 13.05.2025 |
SB2025051380 SB20250521103 SB2025052950 and 11 more |
||
| #VU75664 - Exposure of sensitive information to an unauthorized actor CVE-2023-30861 |
CWE-200 | Medium | 2.2.5, 2.3.2 | 02.05.2023 |
SB2023050221 SB2023052227 SB2023052228 and 44 more |
||
| #VU19269 - Improper input validation CVE-2019-1010083 |
CWE-20 | Medium | 1.0 | 19.07.2019 |
SB2019072205 SB2021062302 SB2023042037 and 1 more |
||
| #VU18150 - Improper input validation CVE-2018-1000656 |
CWE-20 | Medium | 0.12.3 | 08.04.2019 |
SB2019040802 SB2019040213 SB2020060113 and 4 more |