By weakness (CWE)

CWE-620: related vulnerabilities

CVEs classified under CWE-620. Understanding the weakness class helps prioritize systemic fixes over one-off patches.

1 published vulnerability

  • CVE-2025-71337HIGH 8.3

    Flowise versions 3.0.7 and earlier contain a flaw that lets any logged-in user change their account email address without verifying the change with the original email or re-entering their password. Since email serves as both the login identifier and the channel for password recovery, an attacker with account access can silently redirect recovery emails to an attacker-controlled address, enabling complete account takeover. This is a high-severity issue because it removes critical safeguards that normally protect email changes—the two most common identity verification methods in web applications.