Vulnerabilities > Infiniflow > Ragflow > 0.12.0
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2025-03-20 | CVE-2024-12450 | Server-Side Request Forgery (SSRF) vulnerability in Infiniflow Ragflow 0.12.0 In infiniflow/ragflow versions 0.12.0, the `web_crawl` function in `document_app.py` contains multiple vulnerabilities. | 9.8 |
2025-03-20 | CVE-2024-12779 | Unspecified vulnerability in Infiniflow Ragflow 0.12.0 A Server-Side Request Forgery (SSRF) vulnerability exists in infiniflow/ragflow version 0.12.0. | 7.5 |
2025-03-20 | CVE-2024-12869 | Unspecified vulnerability in Infiniflow Ragflow 0.12.0 In infiniflow/ragflow version v0.12.0, there is an improper authentication vulnerability that allows a user to view another user's invite list. | 4.3 |
2025-03-20 | CVE-2024-12871 | Unspecified vulnerability in Infiniflow Ragflow 0.12.0 An XSS vulnerability in infiniflow/ragflow version 0.12.0 allows an attacker to upload a malicious PDF file to the knowledge base. | 5.4 |