Casdoor
Casbin · 12 CVEs
CVE-2026-6815
May 11, 2026
Casdoor Webhook URL server-side request forgery
Apr 3, 2026
Casdoor dangerouslySetInnerHTML cross site scripting
Apr 3, 2026
Casdoor OAuth Authorization Request redirect
Apr 3, 2026
GHSL-2024-036: Reflected XSS in QrCodePage.js
Aug 20, 2024
GHSL-2024-035: Casdoor CORS misconfiguration
Aug 20, 2024
An issue discovered in casdoor v1.636.0 allows attackers to obtain sensitive information via the ssh.InsecureIgnoreHost…
Aug 1, 2024
Casdoor Configuration File app.conf file access
Jun 2, 2024
Casdoor v1.331.0 and below was discovered to contain a Cross-Site Request Forgery (CSRF) in the endpoint /api/set-passw…
Jun 22, 2023
Casdoor before v1.126.1 was discovered to contain an arbitrary file deletion vulnerability via the uploadFile function.
Dec 7, 2022
Casdoor v1.97.3 was discovered to contain an arbitrary file write vulnerability via the fullFilePath parameter at /api/…
Sep 9, 2022
The query API in Casdoor before 1.13.1 has a SQL injection vulnerability related to the field and value parameters, as…
Jan 29, 2022
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-6815 | CVE-2026-6815 | MEDIUM | 0.59% | May 11, 2026 |
| CVE-2026-5469 | Casdoor Webhook URL server-side request forgery | MEDIUM | 0.57% | Apr 3, 2026 |
| CVE-2026-5468 | Casdoor dangerouslySetInnerHTML cross site scripting | MEDIUM | 0.32% | Apr 3, 2026 |
| CVE-2026-5467 | Casdoor OAuth Authorization Request redirect | MEDIUM | 0.43% | Apr 3, 2026 |
| CVE-2024-41658 | GHSL-2024-036: Reflected XSS in QrCodePage.js | MEDIUM | 0.45% | Aug 20, 2024 |
| CVE-2024-41657 | GHSL-2024-035: Casdoor CORS misconfiguration | HIGH | 0.79% | Aug 20, 2024 |
| CVE-2024-41264 | An issue discovered in casdoor v1.636.0 allows attackers to obtain sensitive information via the ssh.InsecureIgnoreHostKey() method. | MEDIUM | 0.46% | Aug 1, 2024 |
| CVE-2024-5587 | Casdoor Configuration File app.conf file access | MEDIUM | 0.47% | Jun 2, 2024 |
| CVE-2023-34927 | Casdoor v1.331.0 and below was discovered to contain a Cross-Site Request Forgery (CSRF) in the endpoint /api/set-password. This vulnerability allows attackers… | MEDIUM | 3.07% | Jun 22, 2023 |
| CVE-2022-44942 | Casdoor before v1.126.1 was discovered to contain an arbitrary file deletion vulnerability via the uploadFile function. | HIGH | 0.90% | Dec 7, 2022 |
| CVE-2022-38638 | Casdoor v1.97.3 was discovered to contain an arbitrary file write vulnerability via the fullFilePath parameter at /api/upload-resource. | CRITICAL | 1.23% | Sep 9, 2022 |
| CVE-2022-24124 | The query API in Casdoor before 1.13.1 has a SQL injection vulnerability related to the field and value parameters, as demonstrated by api/get-organizations. | HIGH | 55.30% | Jan 29, 2022 |
Showing 1 to 12 of 12 CVEs