ragflow
infiniflow- Product type
- Other
- Catalog vulnerabilities
- 20
Severity across 11 analyzed records
Verify to analyze this security profile
en
Severity across 11 analyzed records
Verify to analyze this security profile
As of 09/19/2026, within CyStack's analyzed data, ragflow has 3 security vulnerabilities published in the last 90 days. Of these, 1 is rated High or Critical. None of these vulnerabilities is listed in the CISA KEV catalog. CyStack recommends that organizations and individual users remediate applicable vulnerabilities as soon as possible.
CyStack does not yet have sufficient official-source data to identify the latest version of ragflow and determine which vulnerabilities affect that version.
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan| Vulnerability | Exploitation status | Fix | Published | Severity |
|---|---|---|---|---|
CVE-2026-93013RAGFlow through 0.27.2 Tenant Import Endpoints Path Traversal | Exploitation statusNot confirmed | FixYes | Published09/17/2026 | SeverityMedium |
CVE-2026-75898RAGFlow < 0.26.3 - Server-Side Request Forgery via Agent Invoke Component | Exploitation statusPublic exploit | FixYes | Published08/18/2026 | SeverityHigh |
CVE-2026-58579RAGFlow < 0.26.3 - Stored Cross-Site Scripting via Agent Pipeline Node Name | Exploitation statusPublic exploit | FixYes | Published07/02/2026 | SeverityMedium |
CVE-2026-45312RAGFlow: Server-Side Template Injection in Prompt Generator leads to Remote Code Execution | Exploitation statusPublic exploit | FixNot confirmed | Published05/29/2026 | SeverityCritical |
CVE-2026-28797RAGFlow: Server-Side Template Injection (SSTI) leading to Remote Code Execution (RCE) in Agent "Text Processing" Component | Exploitation statusPublic exploit | FixNot confirmed | Published04/03/2026 | SeverityHigh |
CVE-2026-24770RAGFlow Affected by Zip Slip Remote Code Execution (RCE) in MinerUParser | Exploitation statusPublic exploit | FixNot confirmed | Published01/27/2026 | SeverityCritical |
CVE-2025-69286RAGFlow has Predictable Token Generation Leading to Authentication Bypass Vulnerability | Exploitation statusPublic exploit | FixNot confirmed | Published12/31/2025 | SeverityHigh |
CVE-2025-68700RAGFlow Remote Code Execution Vulnerability | Exploitation statusPublic exploit | FixNot confirmed | Published12/31/2025 | SeverityHigh |
CVE-2025-51462 | Exploitation statusPublic exploit | FixNot confirmed | Published07/22/2025 | SeverityMedium |
CVE-2025-48187 | Exploitation statusPublic exploit | FixNot confirmed | Published05/17/2025 | SeverityCritical |
CVE-2024-12779SSRF in infiniflow/ragflow | Exploitation statusPublic exploit | FixNot confirmed | Published03/20/2025 | SeverityMedium |
CVE-2024-12869Improper Authentication in infiniflow/ragflow | Exploitation statusPublic exploit | FixNot confirmed | Published03/20/2025 | SeverityMedium |
CVE-2024-12871Stored Cross-site Scripting (XSS) in infiniflow/ragflow | Exploitation statusPublic exploit | FixNot confirmed | Published03/20/2025 | SeverityMedium |
CVE-2024-12450RCE, Full Read SSRF, and Arbitrary File Read in infiniflow/ragflow | Exploitation statusPublic exploit | FixYes | Published03/20/2025 | SeverityMedium |
CVE-2024-12433Remote Code Execution in infiniflow/ragflow | Exploitation statusPublic exploit | FixYes | Published03/20/2025 | SeverityCritical |
CVE-2024-12880Partial Account Takeover due to Insecure Data Querying in infiniflow/ragflow | Exploitation statusPublic exploit | FixNot confirmed | Published03/20/2025 | SeverityHigh |
CVE-2025-27135RAGFlow SQL Injection vulnerability | Exploitation statusPublic exploit | FixNot confirmed | Published02/25/2025 | SeverityHigh |
CVE-2025-25282Potential Insecure Direct Object Reference (IDOR) vulnerability in ragflow | Exploitation statusPublic exploit | FixNot confirmed | Published02/21/2025 | SeverityHigh |
CVE-2024-53450 | Exploitation statusPublic exploit | FixNot confirmed | Published12/09/2024 | SeverityHigh |
CVE-2024-10131Remote Code Execution in infiniflow/ragflow | Exploitation statusPublic exploit | FixNot confirmed | Published10/19/2024 | SeverityHigh |