Nifi
Vendor:
First CVE: Jun 12, 2017 · Active for 9 years
50
Total CVEs
More Total CVEs than 98% of tracked products
5.0
Avg CVEs / Year
Higher CVE frequency than 87% of tracked products
6.9
Avg CVSS
Higher Avg CVSS than 40% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Nifi over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 12, 2017
9 years ago
Most Recent CVE
Jun 22, 2026
32 days ago
CVE Severity & Scoring
Nifi50 CVEs
50%
44%
All CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local2 (4.0%)
Network48 (96.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low47 (94.0%)
High3 (6.0%)
Unknown0 (0.0%)
User Interaction
None39 (78.0%)
Unknown0 (0.0%)
Required11 (22.0%)
Privileges Required
Low20 (40.0%)
High4 (8.0%)
None26 (52.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (50 CVEs).
50 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-34468HIGH The DBCPConnectionPool and HikariCPConnectionPool Controller Services in Apache NiFi 0.0.2 through 1.21.0 allow an authenticated and authorized user to configure a Database URL wit | Jun 12, 2023 | 8.8 | 74 | NO | YES |
CVE-2020-27223MEDIUM In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accept headers with a large number of “quality | Feb 26, 2021 | 5.3 | 61 | NO | NO |
CVE-2019-10086HIGH In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property | Aug 20, 2019 | 7.3 | 39 | NO | NO |
CVE-2026-44914HIGH Apache NiFi 1.12.0 through 2.9.0 are missing authorization when replacing Process Groups that include extension components with specific Required Permissions based on the Restricte | Jun 22, 2026 | 7.2 | 34 | NO | NO |
CVE-2026-39816HIGH The optional extension component TinkerpopClientService is missing the Restricted annotation with the Execute Code Required Permission in Apache NiFi 2.0.0-M1 through 2.8.0. The Ti | May 8, 2026 | 8.8 | 34 | NO | NO |
CVE-2026-44913HIGH Improper escaping of database table names in the CaptureChangeMySQL Processor included with Apache NiFi 1.2.0 through 2.9.0 allows for injecting SQL commands using crafted naming. | Jun 22, 2026 | 7.2 | 32 | NO | NO |
CVE-2017-15697CRITICAL A malicious X-ProxyContextPath or X-Forwarded-Context header containing external resources or embedded code could cause remote code execution. The fix to properly handle these head | Jan 23, 2018 | 9.8 | 32 | NO | NO |
CVE-2026-44911MEDIUM Authorization handling for component configuration verification requests in Apache NiFi 1.15.0 through 2.9.0 allows clients with read access to submit proposed configuration proper | Jun 22, 2026 | 6.3 | 30 | NO | NO |
CVE-2024-56512MEDIUM Apache NiFi 1.10.0 through 2.0.0 are missing fine-grained authorization checking for Parameter Contexts, referenced Controller Services, and referenced Parameter Providers, when cr | Dec 28, 2024 | 5.4 | 30 | NO | YES |
CVE-2018-1309CRITICAL Apache NiFi External XML Entity issue in SplitXML processor. Malicious XML content could cause information disclosure or remote code execution. The fix to disable external general | May 23, 2018 | 9.8 | 30 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (50 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
2.0% of CVEs· 96th percentile
Nuclei
1 CVE
2.0% of CVEs· 96th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (50 CVEs).
Media Mentions
Signals from CVEs in this product scope (50 CVEs).
Top CNAs Publishing CVEs For Nifi
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.7.0 | 1 | 8.8 | 0.4% | 0 | 0 |
| 2.0.0 | 3 | 5.1 | 10.6% | 0 | 0 |
| 1.3.0 | 1 | 6.5 | 1.9% | 0 | 0 |
| 1.2.0 | 3 | 6.7 | 2.3% | 0 | 0 |
| 1.15.0 | 1 | 7.3 | 29.8% | 0 | 0 |
| 1.14.0 | 1 | 7.3 | 29.8% | 0 | 0 |
| 1.13.0 | 1 | 5.3 | 78.0% | 0 | 0 |
| 1.1.2 | 3 | 6.7 | 2.3% | 0 | 0 |
| 1.1.1 | 5 | 7.5 | 2.8% | 0 | 0 |
| 1.10.0 | 1 | 5.3 | 4.0% | 0 | 0 |
| 1.1.0 | 6 | 7.1 | 2.6% | 0 | 0 |
| 1.0.1 | 3 | 6.7 | 2.3% | 0 | 0 |
| 1.0.0 | 3 | 6.7 | 2.3% | 0 | 0 |
| 0.7.1 | 2 | 8.7 | 3.4% | 0 | 0 |
| 0.7.0 | 2 | 8.7 | 3.4% | 0 | 0 |