Title |
Severity |
Exploit |
Date |
Affected Version |
CVE-2025-34267
|
High
|
|
Oct 14, 2025
|
>= 3.0.1 < 3.0.8
|
Flowise is vulnerable to arbitrary file exposure through its ReadFileTool
|
High
|
|
Oct 10, 2025
|
< 3.0.8
|
CVE-2025-61913
|
Critical
|
|
Oct 9, 2025
|
< 3.0.8
|
CVE-2025-61687
|
High
|
|
Oct 8, 2025
|
== 3.0.7
>= 3.0.7 < 3.0.8
|
CVE-2025-55346
|
Critical
|
|
Oct 6, 2025
|
<= 2.2.7-patch.1
|
CVE-2025-29192
|
Medium
|
|
Oct 3, 2025
|
< 3.0.5
|
CVE-2025-50538
|
Critical
|
|
Oct 3, 2025
|
< 3.0.8
|
Flowise vulnerable to XSS
|
Medium
|
|
Oct 3, 2025
|
< 3.0.8
|
Flowise has unsandboxed remote code execution via Custom MCP
|
High
|
|
Sep 15, 2025
|
>= 2.2.7-patch.1 < 3.0.6
|
Flowise has arbitrary file access due to missing chat flow id validation
|
Critical
|
|
Sep 15, 2025
|
>= 2.2.8 < 3.0.6
|