Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
7.1
CVE-2026-81659
- EPSS 0.3%
- Veröffentlicht 27.08.2026 10:07:30
- Zuletzt bearbeitet 28.08.2026 15:28:32
Affected versions of Flowintel allow attacker-controlled note content to be processed by Pandoc and XeLaTeX during PDF export in a way that can cause local files on the Flowintel server to be read and incorporated into the generated export.
6.9
CVE-2026-69075
- EPSS 0.29%
- Veröffentlicht 03.08.2026 08:46:59
- Zuletzt bearbeitet 26.08.2026 16:49:18
FlowIntel is affected by a stored cross-site scripting vulnerability through multiple user-controlled or administrator-controlled fields. Persisted values—including case titles, ticket identifiers, recurring-case information, user profile attributes...
9.9
CVE-2026-9813
- EPSS 0.23%
- Veröffentlicht 28.05.2026 09:27:26
- Zuletzt bearbeitet 04.06.2026 18:03:33
FlowIntel up to version 3.3.0 contains a server-side request forgery (SSRF) vulnerability in the external reference URL probe functionality in app/case/task.py. An attacker who can submit an external reference URL can cause the application server to ...