Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
50,274
Mitigations
Mitigation rules
16,213
No official patch
13,190
In triage
1,139
Published soon
18
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
flowise
<= 3.1.2
NPM: Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability
9.5
3 minutes ago
flowise-components
<= 3.1.2
NPM: Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability
9.5
3 minutes ago
flowise
<= 3.1.2
NPM: Flowise: Broken Access Control in Stripe Subscription Endpoints Allows Cross-Tenant Billing Manipulation
8.3
8 minutes ago
flowise
<= 3.1.3
NPM: Flowise: Unauthenticated Credential Abuse via Text-to-Speech Endpoint Allows Unauthorized Use of Private Chatflow TTS Credentials
6.3
13 minutes ago
flowise
<= 3.1.2
NPM: Flowise: Missing Authorization on Execution Update Endpoint
7.1
14 minutes ago
flowise
<= 3.1.2
NPM: Flowise: Cross-Workspace OAuth2 Credential Metadata Leak
7.6
1 hour ago
flowise
<= 3.1.2
NPM: Flowise: Incomplete Credential Redaction Exposes Secrets via API
6.5
1 hour ago
flowise
<= 3.1.2
NPM: Flowise: Information Disclosure in GET /api/v1/upsert-history returns the entire server-wide upsert history
8.3
1 hour ago
flowise
<= 3.1.2
NPM: Flowise: Cross-workspace credential IDOR in openai-assistants-vector-store
7.1
1 hour ago
flowise
<= 3.1.2
NPM: Flowise: RCE via CSVAgent csvFile data URI base64 segment is interpolated into Python source without validation
9.4
1 hour ago
flowise-components
<= 3.1.2
NPM: Flowise: RCE via CSVAgent csvFile data URI base64 segment is interpolated into Python source without validation
9.4
1 hour ago
flowise
<= 3.1.2
NPM: Flowise: Authenticated arbitrary file write in the `S3 Directory` document loader via unsanitized S3 object keys
7.2
1 hour ago
flowise-components
<= 3.1.2
NPM: Flowise: Authenticated arbitrary file write in the `S3 Directory` document loader via unsanitized S3 object keys
7.2
1 hour ago
flowise
<= 3.1.2
NPM: Flowise: RBAC Bypass Leading to Unauthorized Workspace Variables Disclosure
7.1
1 hour ago
flowise
<= 3.1.2
NPM: Flowise: Pyodide validator Unicode homoglyph bypass leads to RCE
9.5
2 hours ago
flowise-components
<= 3.1.2
NPM: Flowise: Pyodide validator Unicode homoglyph bypass leads to RCE
9.5
2 hours ago
flowise
<= 3.1.2
NPM: Flowise: CVE-2025-8943 Patch Bypass: npm_config_yes bypasses MCP environment variable blocklist (Unauthenticated RCE)
8.7
2 hours ago
flowise-components
<= 3.1.2
NPM: Flowise: CVE-2025-8943 Patch Bypass: npm_config_yes bypasses MCP environment variable blocklist (Unauthenticated RCE)
8.7
2 hours ago
flowise
<= 3.1.2
NPM: Flowise: `DELETE /api/v1/chatflows/:id` does not validate resource type, allowing `agentflows:delete` and `chatflows:delete` to delete each other’s flow type
7.1
2 hours ago
flowise
<= 3.1.2
NPM: Flowise RCE via SQLite Record Manager Node
9.4
3 hours ago
Load more