Vulnerabilities > Flower Project

DATE CVE VULNERABILITY TITLE RISK
2022-06-02 CVE-2022-30034 Improper Authentication vulnerability in Flower Project Flower
Flower, a web UI for the Celery Python RPC framework, all versions as of 05-02-2022 is vulnerable to an OAuth authentication bypass.
network
low complexity
flower-project CWE-287
8.6
2019-09-28 CVE-2019-16926 Cross-site Scripting vulnerability in Flower Project Flower 1.0.0
Flower 0.9.3 has XSS via a crafted worker name.
network
low complexity
flower-project CWE-79
6.1
2019-09-28 CVE-2019-16925 Cross-site Scripting vulnerability in Flower Project Flower 1.0.0
Flower 0.9.3 has XSS via the name parameter in an @app.task call.
network
low complexity
flower-project CWE-79
6.1