Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
50,270
Mitigations
Mitigation rules
16,213
No official patch
13,190
In triage
1,139
Published soon
18
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
flowise
<= 3.1.2
NPM: Flowise: RCE via CSVAgent csvFile data URI base64 segment is interpolated into Python source without validation
9.4
20 minutes ago
flowise-components
<= 3.1.2
NPM: Flowise: RCE via CSVAgent csvFile data URI base64 segment is interpolated into Python source without validation
9.4
20 minutes ago
flowise
<= 3.1.2
NPM: Flowise: Authenticated arbitrary file write in the `S3 Directory` document loader via unsanitized S3 object keys
7.2
20 minutes ago
flowise-components
<= 3.1.2
NPM: Flowise: Authenticated arbitrary file write in the `S3 Directory` document loader via unsanitized S3 object keys
7.2
20 minutes ago
flowise
<= 3.1.2
NPM: Flowise: RBAC Bypass Leading to Unauthorized Workspace Variables Disclosure
7.1
20 minutes ago
flowise
<= 3.1.2
NPM: Flowise: Pyodide validator Unicode homoglyph bypass leads to RCE
9.5
33 minutes ago
flowise-components
<= 3.1.2
NPM: Flowise: Pyodide validator Unicode homoglyph bypass leads to RCE
9.5
33 minutes ago
flowise
<= 3.1.2
NPM: Flowise: CVE-2025-8943 Patch Bypass: npm_config_yes bypasses MCP environment variable blocklist (Unauthenticated RCE)
8.7
54 minutes ago
flowise-components
<= 3.1.2
NPM: Flowise: CVE-2025-8943 Patch Bypass: npm_config_yes bypasses MCP environment variable blocklist (Unauthenticated RCE)
8.7
54 minutes ago
flowise
<= 3.1.2
NPM: Flowise: `DELETE /api/v1/chatflows/:id` does not validate resource type, allowing `agentflows:delete` and `chatflows:delete` to delete each other’s flow type
7.1
1 hour ago
flowise
<= 3.1.2
NPM: Flowise RCE via SQLite Record Manager Node
9.4
1 hour ago
flowise-components
<= 3.1.2
NPM: Flowise RCE via SQLite Record Manager Node
9.4
1 hour ago
flowise
<= 3.1.2
NPM: Flowise: Unauthenticated Property Injection into Flow Execution Context via Ungated `overrideConfig` Spread in Prediction API
8.8
2 hours ago
flowise
<= 3.1.2
NPM: Flowise: SSRF Protection Bypass via IPv4-Mapped IPv6 Addresses
7.6
2 hours ago
flowise
<= 3.1.2
NPM: Remote Code Execution Vulnerability in CSVAgent
9.4
2 hours ago
flowise-components
<= 3.1.2
NPM: Remote Code Execution Vulnerability in CSVAgent
9.4
2 hours ago
flowise
<= 3.1.2
NPM: Flowise: CSV Agent Remote Code Execution via Pyodide Code Injection — Root Shell Verified
9.2
2 hours ago
flowise-components
<= 3.1.2
NPM: Flowise: CSV Agent Remote Code Execution via Pyodide Code Injection — Root Shell Verified
9.2
2 hours ago
flowise
<= 3.1.2
NPM: Flowise: RCE via NodeVM Sandbox Escape in executeJavaScriptCode() nodeVMOptions Override
9.4
2 hours ago
flowise-components
<= 3.1.2
NPM: Flowise: RCE via NodeVM Sandbox Escape in executeJavaScriptCode() nodeVMOptions Override
9.4
2 hours ago
Load more