VYPR
Vendor

RAGFlow

Products
1
CVEs
2
Across products
2
Status
Private

Products

1

Recent CVEs

2
  • CVE-2024-53450HigDec 9, 2024
    risk 0.49cvss 7.5epss 0.01

    RAGFlow 0.13.0 suffers from improper access control in document-hooks.ts, allowing unauthorized access to user documents.

  • CVE-2025-51462MedJul 22, 2025
    risk 0.00cvss 6.1epss 0.00

    Stored Cross-site Scripting (XSS) vulnerability in api.apps.dialog_app.set_dialog in RAGFlow 0.17.2 allows remote attackers to execute arbitrary JavaScript via crafted input to the assistant greeting field, which is stored unsanitised and rendered using a markdown component with…