Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Infiniflow

First CVE: Oct 19, 2024Active for: 2 yearsTotal CVEs: 17
42.2
VTI Score
High

Infiniflow maintains a narrowly focused portfolio centered on RAGFlow, a retrieval-augmented generation platform positioned in the document-processing and AI application stack. Its vulnerability profile skews toward critical-severity outcomes and concentrates on access-control and code-execution weakness classes, including authorization bypass through user-controlled keys, code injection, cross-site scripting, and OS command injection—a pattern reflecting the document-handling and server-side execution demands of a content-processing application. Current severity and exploitation figures are shown alongside this summary.

FAUCET AI Generated
17
Total CVEs
More Total CVEs than 95% of tracked vendors
5.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 98% of tracked vendors
8.0
Avg CVSS Score
Higher Avg CVSS Score than 78% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Infiniflow over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 19, 2024
21 months ago
Most Recent CVE
Jul 2, 2026
23 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (17 CVEs).

17 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-24770CRITICAL
RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In version 0.23.1 and possibly earlier versions, the MinerU parser contains a "Zip Slip" vulnerability, allow
Jan 27, 20269.833NONO
CVE-2026-28797HIGH
RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In versions 0.24.0 and prior, a Server-Side Template Injection (SSTI) vulnerability exists in RAGFlow's Agent
Apr 3, 20268.831NONO
CVE-2025-27135CRITICAL
RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. Versions 0.15.1 and prior are vulnerable to SQL injection. The ExeSQL component extracts the SQL statement fr
Feb 25, 20259.830NONO
CVE-2025-68700HIGH
RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In versions prior to 0.23.0, a low-privileged authenticated user (normal login account) can execute arbitrary
Dec 31, 20258.828NONO
CVE-2025-48187CRITICAL
RAGFlow through 0.18.1 allows account takeover because it is possible to conduct successful brute-force attacks against email verification codes to perform arbitrary account regist
May 17, 20259.828NONO
CVE-2025-69286CRITICAL
RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In versions prior to 0.22.0, the use of an insecure key generation algorithm in the API key and beta (assista
Dec 31, 20259.827NONO
CVE-2024-12433CRITICAL
A vulnerability in infiniflow/ragflow versions v0.12.0 allows for remote code execution. The RPC server in RagFlow uses a hard-coded AuthKey 'authkey=b'infiniflow-token4kevinhu'' w
Mar 20, 20259.827NONO
CVE-2024-10131HIGH
The `add_llm` function in `llm_app.py` in infiniflow/ragflow version 0.11.0 contains a remote code execution (RCE) vulnerability. The function uses user-supplied input `req['llm_fa
Oct 19, 20248.826NONO
CVE-2026-58579MEDIUM
RAGFlow before 0.26.3 stores an agent pipeline (DSL) node name without sanitization: the agent update endpoint normalizes the submitted DSL via normalize_dsl, which only performs J
Jul 2, 20265.425NONO
CVE-2024-12450CRITICAL
In infiniflow/ragflow versions 0.12.0, the `web_crawl` function in `document_app.py` contains multiple vulnerabilities. The function does not filter URL parameters, allowing attack
Mar 20, 20259.825NONO
View all 17 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products17 CVEs
29%
35%
35%
Severity distribution among all CVEs352,708 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network17 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low17 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None14 (82.4%)
Unknown0 (0.0%)
Required3 (17.6%)
Privileges Required
Low8 (47.1%)
High0 (0.0%)
None9 (52.9%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (17 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Infiniflow.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Infiniflow — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Infiniflow's Products

View all 4 CNAs →

Top CWEs