Flower Project maintains a real-time task monitoring and management application whose vulnerability profile centers on the core Flower product and recurs through web-application input-handling issues such as cross-site scripting and improper authentication. Treat this as a compact vendor footprint; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Flower Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-30034HIGH Flower, a web UI for the Celery Python RPC framework, all versions as of 05-02-2022 is vulnerable to an OAuth authentication bypass. An attacker could then access the Flower API to | Jun 2, 2022 | 8.6 | 23 | NO | NO |
CVE-2019-16925MEDIUM Flower 0.9.3 has XSS via the name parameter in an @app.task call. NOTE: The project author stated that he doesn't think this is a valid vulnerability. Worker name and task name are | Sep 28, 2019 | 6.1 | 20 | NO | NO |
CVE-2019-16926MEDIUM Flower 0.9.3 has XSS via a crafted worker name. NOTE: The project author stated that he doesn't think this is a valid vulnerability. Worker name and task name aren’t user facing co | Sep 28, 2019 | 6.1 | 19 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Flower Project.
Media articles that mention a CVE ID that affects a product developed by Flower Project — matched by CVE ID, not by vendor name.