Ragflow
Infiniflow · 20 CVEs
RAGFlow through 0.27.2 Tenant Import Endpoints Path Traversal
Sep 17, 2026
RAGFlow < 0.26.3 - Server-Side Request Forgery via Agent Invoke Component
Aug 18, 2026
RAGFlow < 0.26.3 - Stored Cross-Site Scripting via Agent Pipeline Node Name
Jul 2, 2026
RAGFlow: Server-Side Template Injection in Prompt Generator leads to Remote Code Execution
May 29, 2026
RAGFlow: Server-Side Template Injection (SSTI) leading to Remote Code Execution (RCE) in Agent "Text Processing" Compon…
Apr 3, 2026
RAGFlow Affected by Zip Slip Remote Code Execution (RCE) in MinerUParser
Jan 27, 2026
RAGFlow has Predictable Token Generation Leading to Authentication Bypass Vulnerability
Dec 31, 2025
RAGFlow Remote Code Execution Vulnerability
Dec 31, 2025
Stored Cross-site Scripting (XSS) vulnerability in api.apps.dialog_app.set_dialog in RAGFlow 0.17.2 allows remote attac…
Jul 22, 2025
RAGFlow through 0.18.1 allows account takeover because it is possible to conduct successful brute-force attacks against…
May 17, 2025
SSRF in infiniflow/ragflow
Mar 20, 2025
Improper Authentication in infiniflow/ragflow
Mar 20, 2025
Stored Cross-site Scripting (XSS) in infiniflow/ragflow
Mar 20, 2025
RCE, Full Read SSRF, and Arbitrary File Read in infiniflow/ragflow
Mar 20, 2025
Remote Code Execution in infiniflow/ragflow
Mar 20, 2025
Partial Account Takeover due to Insecure Data Querying in infiniflow/ragflow
Mar 20, 2025
RAGFlow SQL Injection vulnerability
Feb 25, 2025
Potential Insecure Direct Object Reference (IDOR) vulnerability in ragflow
Feb 21, 2025
RAGFlow 0.13.0 suffers from improper access control in document-hooks.ts, allowing unauthorized access to user document…
Dec 9, 2024
Remote Code Execution in infiniflow/ragflow
Oct 19, 2024
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-93013 | RAGFlow through 0.27.2 Tenant Import Endpoints Path Traversal | MEDIUM | 0.51% | Sep 17, 2026 |
| CVE-2026-75898 | RAGFlow < 0.26.3 - Server-Side Request Forgery via Agent Invoke Component | HIGH | 0.39% | Aug 18, 2026 |
| CVE-2026-58579 | RAGFlow < 0.26.3 - Stored Cross-Site Scripting via Agent Pipeline Node Name | MEDIUM | 0.30% | Jul 2, 2026 |
| CVE-2026-45312 | RAGFlow: Server-Side Template Injection in Prompt Generator leads to Remote Code Execution | CRITICAL | 0.52% | May 29, 2026 |
| CVE-2026-28797 | RAGFlow: Server-Side Template Injection (SSTI) leading to Remote Code Execution (RCE) in Agent "Text Processing" Component | HIGH | 0.56% | Apr 3, 2026 |
| CVE-2026-24770 | RAGFlow Affected by Zip Slip Remote Code Execution (RCE) in MinerUParser | CRITICAL | 1.40% | Jan 27, 2026 |
| CVE-2025-69286 | RAGFlow has Predictable Token Generation Leading to Authentication Bypass Vulnerability | HIGH | 0.80% | Dec 31, 2025 |
| CVE-2025-68700 | RAGFlow Remote Code Execution Vulnerability | HIGH | 0.72% | Dec 31, 2025 |
| CVE-2025-51462 | Stored Cross-site Scripting (XSS) vulnerability in api.apps.dialog_app.set_dialog in RAGFlow 0.17.2 allows remote attackers to execute arbitrary JavaScript via… | MEDIUM | 0.29% | Jul 22, 2025 |
| CVE-2025-48187 | RAGFlow through 0.18.1 allows account takeover because it is possible to conduct successful brute-force attacks against email verification codes to perform arb… | CRITICAL | 0.54% | May 17, 2025 |
| CVE-2024-12779 | SSRF in infiniflow/ragflow | HIGH | 0.65% | Mar 20, 2025 |
| CVE-2024-12869 | Improper Authentication in infiniflow/ragflow | MEDIUM | 0.54% | Mar 20, 2025 |
| CVE-2024-12871 | Stored Cross-site Scripting (XSS) in infiniflow/ragflow | MEDIUM | 0.39% | Mar 20, 2025 |
| CVE-2024-12450 | RCE, Full Read SSRF, and Arbitrary File Read in infiniflow/ragflow | CRITICAL | 1.32% | Mar 20, 2025 |
| CVE-2024-12433 | Remote Code Execution in infiniflow/ragflow | CRITICAL | 1.69% | Mar 20, 2025 |
| CVE-2024-12880 | Partial Account Takeover due to Insecure Data Querying in infiniflow/ragflow | MEDIUM | 0.68% | Mar 20, 2025 |
| CVE-2025-27135 | RAGFlow SQL Injection vulnerability | HIGH | 0.62% | Feb 25, 2025 |
| CVE-2025-25282 | Potential Insecure Direct Object Reference (IDOR) vulnerability in ragflow | HIGH | 0.49% | Feb 21, 2025 |
| CVE-2024-53450 | RAGFlow 0.13.0 suffers from improper access control in document-hooks.ts, allowing unauthorized access to user documents. | HIGH | 0.54% | Dec 9, 2024 |
| CVE-2024-10131 | Remote Code Execution in infiniflow/ragflow | HIGH | 1.14% | Oct 19, 2024 |
Showing 1 to 20 of 20 CVEs