CVE security advisories and vulnerability history for n8n by n8n-io.
64
Total CVEs
Published
1
In CISA KEV
Exploited in the wild
7
Public exploits
With known exploit
7.8
Avg CVSS
2023–2026
Last updated
Overview
n8n-io n8n has 64 published CVE records since 2023, of which 1 are in CISA's Known Exploited Vulnerabilities catalog and 7 have a known public exploit. The average CVSS base score across scored CVEs is 7.8.
This page aggregates every publicly disclosed vulnerability (CVE) affecting n8n-io n8n, with a severity breakdown, the affected and patched versions, the most common weakness types, and the full CVE list.
Severity and exploitation
How the CVSS severity of n8n-io n8n's CVEs breaks down, plus how many are exploited in the wild or have public exploit code.
Critical21
High23
Medium20
Low0
In CISA’s Known Exploited Vulnerabilities catalog
1
One of n8n-io n8n's CVEs is confirmed exploited in the wild.
Public exploits
7
7 of n8n-io n8n's CVEs have a known public exploit available.
Affected versions and CVEs
Browse every n8n-io n8n version named in a CVE, then pick one to see only the CVEs that affect it.
Common questions about n8n-io n8n vulnerabilities.
How many CVEs does n8n-io n8n have?
n8n-io n8n has 64 published CVE records since 2023.
How many n8n-io n8n CVEs are in CISA KEV?
Yes — 1 of n8n-io n8n's CVEs are listed in CISA's Known Exploited Vulnerabilities catalog, confirmed exploited in the wild and carrying a CISA remediation deadline.
Are there public exploits for n8n-io n8n vulnerabilities?
Yes — 7 of n8n-io n8n's CVEs have a known public exploit.
Which versions of n8n-io n8n are affected?
1,989 distinct n8n-io n8n versions are named across its CVEs. Use the version filter above to see the CVEs affecting a specific version.
What are the most common weakness types in n8n-io n8n CVEs?
n8n-io n8n's CVEs most often map to these CWE weakness types: CWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')), CWE-94 (Improper Control of Generation of Code ('Code Injection')), CWE-89 (Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')), CWE-20 (Improper Input Validation).
How many critical n8n-io n8n vulnerabilities are there?
n8n-io n8n has 21 critical and 23 high-severity CVEs.
What is the average severity of n8n-io n8n CVEs?
The average CVSS base score across n8n-io n8n's scored CVEs is 7.8.