Back to Database
Status published
High
CVE-2025-29192
Flowise before 3.0.5 allows XSS via a FORM element and...
Vulnerability Description
Flowise before 3.0.5 allows XSS via a FORM element and an INPUT element when an admin views the chat log.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-29192
Credits & Attribution
No credits recorded in the NVD database.
References
More from FlowiseAI
View All →CVE-2025-61913
Flowise is vulnerable to arbitrary file read, arbitrary file write
Critical
10
CVE-2025-61687
FlowiseAI/Flosise has File Upload vulnerability
High
8.3
CVE-2025-59528
Flowise has Remote Code Execution vulnerability
Critical
10
CVE-2025-59527
FlowiseAI/Flowise has Server-Side Request Forgery (SSRF) vulnerability
High
7.5
CVE-2025-59434
Critical Multi-Tenant Variable Disclosure in Flowise Cloud via Custom JavaScript Function
Critical
9.6
Affected Vendor
FlowiseAI
View all reports →Affected Software
Flowise
Vulnerable Versions:
0
Timeline
Official Publish:
October 6th, 2025
Last Modified:
October 6th, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N