Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-2830 | Flowise < 2.1.1 suffers from a Stored Cross-Site vulnerability due to a lack of input sanitization in Flowise Chat Embed < 2.0.0. |
Github GHSA |
GHSA-m5p9-xvxj-64c8 | Flowise and Flowise Chat Embed vulnerable to Stored Cross-site Scripting |
| Link | Providers |
|---|---|
| https://www.tenable.com/security/research/tra-2024-40 |
|
Fri, 11 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Mon, 30 Sep 2024 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Flowiseai embed
|
|
| CPEs | cpe:2.3:a:flowiseai:embed:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Flowiseai embed
|
Tue, 24 Sep 2024 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Flowiseai
Flowiseai flowise |
|
| CPEs | cpe:2.3:a:flowiseai:flowise:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Flowiseai
Flowiseai flowise |
|
| Metrics |
ssvc
|
Tue, 24 Sep 2024 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Flowise < 2.1.1 suffers from a Stored Cross-Site vulnerability due to a lack of input sanitization in Flowise Chat Embed < 2.0.0. | |
| Title | Flowise Stored Cross-Site Scripting | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: tenable
Published:
Updated: 2024-09-24T13:47:35.323Z
Reserved: 2024-09-24T12:56:09.831Z
Link: CVE-2024-9148
Updated: 2024-09-24T13:47:28.084Z
Status : Analyzed
Published: 2024-09-25T01:15:49.297
Modified: 2024-09-30T17:34:12.760
Link: CVE-2024-9148
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA