Ragflow

Infiniflow · 20 CVEs

CVE-2026-93013
MEDIUM

RAGFlow through 0.27.2 Tenant Import Endpoints Path Traversal

Sep 17, 2026

CVE-2026-75898
HIGH

RAGFlow < 0.26.3 - Server-Side Request Forgery via Agent Invoke Component

Aug 18, 2026

CVE-2026-58579
MEDIUM

RAGFlow < 0.26.3 - Stored Cross-Site Scripting via Agent Pipeline Node Name

Jul 2, 2026

CVE-2026-45312
CRITICAL

RAGFlow: Server-Side Template Injection in Prompt Generator leads to Remote Code Execution

May 29, 2026

CVE-2026-28797
HIGH

RAGFlow: Server-Side Template Injection (SSTI) leading to Remote Code Execution (RCE) in Agent "Text Processing" Compon…

Apr 3, 2026

CVE-2026-24770
CRITICAL

RAGFlow Affected by Zip Slip Remote Code Execution (RCE) in MinerUParser

Jan 27, 2026

CVE-2025-69286
HIGH

RAGFlow has Predictable Token Generation Leading to Authentication Bypass Vulnerability

Dec 31, 2025

CVE-2025-68700
HIGH

RAGFlow Remote Code Execution Vulnerability

Dec 31, 2025

CVE-2025-51462
MEDIUM

Stored Cross-site Scripting (XSS) vulnerability in api.apps.dialog_app.set_dialog in RAGFlow 0.17.2 allows remote attac…

Jul 22, 2025

CVE-2025-48187
CRITICAL

RAGFlow through 0.18.1 allows account takeover because it is possible to conduct successful brute-force attacks against…

May 17, 2025

CVE-2024-12779
HIGH

SSRF in infiniflow/ragflow

Mar 20, 2025

CVE-2024-12869
MEDIUM

Improper Authentication in infiniflow/ragflow

Mar 20, 2025

CVE-2024-12871
MEDIUM

Stored Cross-site Scripting (XSS) in infiniflow/ragflow

Mar 20, 2025

CVE-2024-12450
CRITICAL

RCE, Full Read SSRF, and Arbitrary File Read in infiniflow/ragflow

Mar 20, 2025

CVE-2024-12433
CRITICAL

Remote Code Execution in infiniflow/ragflow

Mar 20, 2025

CVE-2024-12880
MEDIUM

Partial Account Takeover due to Insecure Data Querying in infiniflow/ragflow

Mar 20, 2025

CVE-2025-27135
HIGH

RAGFlow SQL Injection vulnerability

Feb 25, 2025

CVE-2025-25282
HIGH

Potential Insecure Direct Object Reference (IDOR) vulnerability in ragflow

Feb 21, 2025

CVE-2024-53450
HIGH

RAGFlow 0.13.0 suffers from improper access control in document-hooks.ts, allowing unauthorized access to user document…

Dec 9, 2024

CVE-2024-10131
HIGH

Remote Code Execution in infiniflow/ragflow

Oct 19, 2024

Showing 1 to 20 of 20 CVEs