Flow
This hub aggregates every CVE we track for Flow, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
25
CVEs tracked
0
Critical
6
High
0
In CISA KEV
Severity distribution
MEDIUM17HIGH6LOW2
Monthly trend
1
0
0
0
1
0
0
0
0
0
2
0
0
0
0
1
0
0
1
0
2
1
0
0
2024-072026-06
Latest CVEs
The 15 most recently published vulnerabilities affecting Flow.
- CVE-2026-22683Windmill < 1.615.0 Operator Role Missing Authorization Checks RCE8.8
- CVE-2026-2742Unauthorized session creation via reserved framework path access5.3
- CVE-2026-2741Zip Slip Path Traversal on Node Unpack6.8
- CVE-2026-1126lwj flow SVG File FormResource.java uploadFile unrestricted upload6.3
- CVE-2025-11655Total.js Flow SVG File unrestricted upload4.7
- CVE-2025-20972Improper verification of intent by broadcast receiver in Samsung Flow prior to version 4.9.17.6 allows local attackers to modify Samsung Flow configuration.6.2
- CVE-2025-20971Improper input validation in Samsung Flow prior to version 4.9.17.6 allows local attackers to access data within Samsung Flow.5.5
- CVE-2024-49407Improper access control in Samsung Flow prior to version 4.9.15.7 allows physical attackers to access data across multiple user profiles.4.6
- CVE-2024-34600Improper verification of intent by broadcast receiver vulnerability in Samsung Flow prior to version 4.9.13.0 allows local attackers to copy image files to external storage.4.4
- CVE-2023-30094A stored cross-site scripting (XSS) vulnerability in TotalJS Flow v10 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the platform name field in the se...5.4
- CVE-2023-21444Improper cryptographic implementation in Samsung Flow for PC 4.9.14.0 allows adjacent attackers to decrypt encrypted messages or inject commands.7.5
- CVE-2023-21443Improper cryptographic implementation in Samsung Flow for Android prior to version 4.9.04 allows adjacent attackers to decrypt encrypted messages or inject commands.7.5
- CVE-2021-31412Possible route enumeration in production mode via RouteNotFoundError view in Vaadin 10, 11-14, and 15-195.3
- CVE-2021-31411Insecure temporary directory usage in frontend build functionality of Vaadin 14 and 15-196.3
- CVE-2021-31408Server session is not invalidated when logout() helper method of Authentication module is used in Vaadin 18-196.3
Product normalization is registry-driven with AI assist and human review. How it works