Known Vulnerabilities for Flow by Typo3
Listed below are 1 of the newest known vulnerabilities associated with "Flow" by "Typo3".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-40948 json | The Keycloak authentication manager in `apache-airflow-providers-keycloak` did not generate or validate the OAuth 2.0 `state`... | Not Provided | 2026-04-18 | 2026-04-20 |
| CVE-2026-40933 json | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, due to unsafe serial... | Not Provided | 2026-04-21 | 2026-04-22 |
| CVE-2026-40591 json | FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.214, the phone-conversation creation flow ... | Not Provided | 2026-04-21 | 2026-04-21 |
| CVE-2026-40590 json | FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.214, the Change Customer modal exposes a �... | Not Provided | 2026-04-21 | 2026-04-21 |
| CVE-2026-40587 json | blueprintUE is a tool to help Unreal Engine developers. Prior to 4.2.0, when a user changes their password via the profile ed... | Not Provided | 2026-04-21 | 2026-04-21 |
| CVE-2026-40582 json | ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the /api/public/user/login endpoint validat... | Not Provided | 2026-04-18 | 2026-04-20 |
| CVE-2026-40302 json | zrok is software for sharing web services, files, and network resources. Prior to version 2.0.1, the proxyUi template engine ... | Not Provided | 2026-04-17 | 2026-04-18 |
| CVE-2026-40162 json | Bugsink is a self-hosted error tracking tool. In 2.1.0, an authenticated file write vulnerability was identified in Bugsink 2... | Not Provided | 2026-04-10 | 2026-04-10 |
| CVE-2026-40098 json | Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Community E... | Not Provided | 2026-04-20 | 2026-04-20 |
| CVE-2026-39865 json | Axios is a promise based HTTP client for the browser and Node.js. Starting in version 1.13.0 and prior to 1.13.2, Axios HTTP/... | Not Provided | 2026-04-08 | 2026-04-13 |