infiniflow
- Total products in the ecosystem
- 2
- Total vulnerabilities (90 days)
- 3
en
Verify to analyze this security profile
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScanAs of 09/19/2026, infiniflow recorded 3 security vulnerabilities in the last 90 days across 1 products, including 1 rated High or above and 0 known exploited vulnerabilities (KEV) that should be prioritized for immediate remediation.
Over the last 90 days, ragflow had the most security vulnerabilities in the infiniflow ecosystem, with 3 vulnerabilities—approximately 100% of the provider's total vulnerabilities during this period.
| Vulnerability | Exploitation status | Fix | Affected product | Published | Severity |
|---|---|---|---|---|---|
CVE-2026-93013RAGFlow through 0.27.2 Tenant Import Endpoints Path Traversal | Exploitation statusNot confirmed | FixYes | Affected productragflow | Published09/17/2026 | SeverityMedium |
CVE-2026-75898RAGFlow < 0.26.3 - Server-Side Request Forgery via Agent Invoke Component | Exploitation statusPublic exploit | FixYes | Affected productragflow | Published08/18/2026 | SeverityHigh |
CVE-2026-58579RAGFlow < 0.26.3 - Stored Cross-Site Scripting via Agent Pipeline Node Name | Exploitation statusPublic exploit | FixYes | Affected productragflow | Published07/02/2026 | SeverityMedium |
CVE-2026-45312RAGFlow: Server-Side Template Injection in Prompt Generator leads to Remote Code Execution | Exploitation statusPublic exploit | FixNot confirmed | Affected productragflow | Published05/29/2026 | SeverityCritical |
CVE-2026-28797RAGFlow: Server-Side Template Injection (SSTI) leading to Remote Code Execution (RCE) in Agent "Text Processing" Component | Exploitation statusPublic exploit | FixNot confirmed | Affected productragflow | Published04/03/2026 | SeverityHigh |
CVE-2026-24770RAGFlow Affected by Zip Slip Remote Code Execution (RCE) in MinerUParser | Exploitation statusPublic exploit | FixNot confirmed | Affected productragflow | Published01/27/2026 | SeverityCritical |
CVE-2025-69286RAGFlow has Predictable Token Generation Leading to Authentication Bypass Vulnerability | Exploitation statusPublic exploit | FixNot confirmed | Affected productragflow | Published12/31/2025 | SeverityHigh |
CVE-2025-68700RAGFlow Remote Code Execution Vulnerability | Exploitation statusPublic exploit | FixNot confirmed | Affected productragflow | Published12/31/2025 | SeverityHigh |
CVE-2025-51462 | Exploitation statusPublic exploit | FixNot confirmed | Affected productNot confirmed | Published07/22/2025 | SeverityMedium |
CVE-2025-48187 | Exploitation statusPublic exploit | FixNot confirmed | Affected productragflow | Published05/17/2025 | SeverityCritical |
CVE-2024-12779SSRF in infiniflow/ragflow | Exploitation statusPublic exploit | FixNot confirmed | Affected productinfiniflow/ragflow | Published03/20/2025 | SeverityMedium |
CVE-2024-12869Improper Authentication in infiniflow/ragflow | Exploitation statusPublic exploit | FixNot confirmed | Affected productinfiniflow/ragflow | Published03/20/2025 | SeverityMedium |
CVE-2024-12871Stored Cross-site Scripting (XSS) in infiniflow/ragflow | Exploitation statusPublic exploit | FixNot confirmed | Affected productinfiniflow/ragflow | Published03/20/2025 | SeverityMedium |
CVE-2024-12450RCE, Full Read SSRF, and Arbitrary File Read in infiniflow/ragflow | Exploitation statusPublic exploit | FixYes | Affected productinfiniflow/ragflow | Published03/20/2025 | SeverityMedium |
CVE-2024-12870Stored Cross-site Scripting (XSS) in infiniflow/ragflow | Exploitation statusPublic exploit | FixNot confirmed | Affected productinfiniflow/ragflow | Published03/20/2025 | SeverityMedium |
CVE-2024-12433Remote Code Execution in infiniflow/ragflow | Exploitation statusPublic exploit | FixYes | Affected productinfiniflow/ragflow | Published03/20/2025 | SeverityCritical |
CVE-2024-12880Partial Account Takeover due to Insecure Data Querying in infiniflow/ragflow | Exploitation statusPublic exploit | FixNot confirmed | Affected productinfiniflow/ragflow | Published03/20/2025 | SeverityHigh |
CVE-2025-27135RAGFlow SQL Injection vulnerability | Exploitation statusPublic exploit | FixNot confirmed | Affected productragflow | Published02/25/2025 | SeverityHigh |
CVE-2025-25282Potential Insecure Direct Object Reference (IDOR) vulnerability in ragflow | Exploitation statusPublic exploit | FixNot confirmed | Affected productragflow | Published02/21/2025 | SeverityHigh |
CVE-2024-53450 | Exploitation statusPublic exploit | FixNot confirmed | Affected productNot confirmed | Published12/09/2024 | SeverityHigh |
CVE-2024-10131Remote Code Execution in infiniflow/ragflow | Exploitation statusPublic exploit | FixNot confirmed | Affected productinfiniflow/ragflow | Published10/19/2024 | SeverityHigh |