infiniflow/ragflow
infiniflow- Product type
- Other
- Catalog vulnerabilities
- 8
Severity across 8 analyzed records
Verify to analyze this security profile
en
Severity across 8 analyzed records
Verify to analyze this security profile
As of 09/19/2026, within CyStack's analyzed data, infiniflow/ragflow has 0 security vulnerabilities published in the last 90 days. Of these, 0 are rated High or Critical. None of these vulnerabilities is listed in the CISA KEV catalog. CyStack recommends that organizations and individual users remediate applicable vulnerabilities as soon as possible.
CyStack does not yet have sufficient official-source data to identify the latest version of infiniflow/ragflow and determine which vulnerabilities affect that version.
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan| Vulnerability | Exploitation status | Fix | Published | Severity |
|---|---|---|---|---|
CVE-2024-12779SSRF in infiniflow/ragflow | Exploitation statusPublic exploit | FixNot confirmed | Published03/20/2025 | SeverityMedium |
CVE-2024-12869Improper Authentication in infiniflow/ragflow | Exploitation statusPublic exploit | FixNot confirmed | Published03/20/2025 | SeverityMedium |
CVE-2024-12871Stored Cross-site Scripting (XSS) in infiniflow/ragflow | Exploitation statusPublic exploit | FixNot confirmed | Published03/20/2025 | SeverityMedium |
CVE-2024-12450RCE, Full Read SSRF, and Arbitrary File Read in infiniflow/ragflow | Exploitation statusPublic exploit | FixYes | Published03/20/2025 | SeverityMedium |
CVE-2024-12870Stored Cross-site Scripting (XSS) in infiniflow/ragflow | Exploitation statusPublic exploit | FixNot confirmed | Published03/20/2025 | SeverityMedium |
CVE-2024-12433Remote Code Execution in infiniflow/ragflow | Exploitation statusPublic exploit | FixYes | Published03/20/2025 | SeverityCritical |
CVE-2024-12880Partial Account Takeover due to Insecure Data Querying in infiniflow/ragflow | Exploitation statusPublic exploit | FixNot confirmed | Published03/20/2025 | SeverityHigh |
CVE-2024-10131Remote Code Execution in infiniflow/ragflow | Exploitation statusPublic exploit | FixNot confirmed | Published10/19/2024 | SeverityHigh |