VendorsCasbincasdoorall versions
Vulnerabilities

Casbin Casdoor

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

11CVEs
CVE-2022-38638
Casdoor v1.97.3 was discovered to contain an arbitrary file write vulnerability via the fullFilePath parameter at /api/upload-resource.
Published 2022-09-09 · Modified
9.1EPSS 0.012
CVE-2024-41657
GHSL-2024-035: Casdoor CORS misconfiguration
Published 2024-08-20 · Analyzed
8.8EPSS 0.008
CVE-2022-44942
Casdoor before v1.126.1 was discovered to contain an arbitrary file deletion vulnerability via the uploadFile function.
Published 2022-12-07 · Modified
8.1EPSS 0.009
CVE-2022-24124
The query API in Casdoor before 1.13.1 has a SQL injection vulnerability related to the field and value parameters, as demonstrated by api/get-organizations.
Published 2022-01-29 · Modified
7.51 PoCEPSS 0.553
CVE-2024-41264
An issue discovered in casdoor v1.636.0 allows attackers to obtain sensitive information via the ssh.InsecureIgnoreHostKey() method.
Published 2024-08-01 · Analyzed
7.5EPSS 0.005
CVE-2026-5469
Casdoor Webhook URL server-side request forgery
Published 2026-04-03 · Analyzed
7.2EPSS 0.006
CVE-2023-34927
Casdoor v1.331.0 and below was discovered to contain a Cross-Site Request Forgery (CSRF) in the endpoint /api/set-password. This vulnerability allows attackers to arbitrarily change the victim user's password via supplying a crafted URL.
Published 2023-06-22 · Modified
6.53 PoCEPSS 0.031
CVE-2024-41658
GHSL-2024-036: Reflected XSS in QrCodePage.js
Published 2024-08-20 · Analyzed
6.1EPSS 0.004
CVE-2026-5467
Casdoor OAuth Authorization Request redirect
Published 2026-04-03 · Analyzed
6.1EPSS 0.004
CVE-2026-6815
CVE-2026-6815
Published 2026-05-11 · Analyzed
5.91 PoCEPSS 0.006
CVE-2026-5468
Casdoor dangerouslySetInnerHTML cross site scripting
Published 2026-04-03 · Analyzed
5.4EPSS 0.003