CVE List

CVE-2025-50538

Critical 8.2

Flowise before 3.0.5 allows XSS via an IFRAME element when an admin views the chat log.

Published October 6, 2025.

Affected software

Get alerts for Flowiseai Flowise

Reference links