VendorsLangGeniusdifyany version
Vulnerabilities

LangGenius Dify any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

14CVEs
CVE-2025-56157
Default credentials in Dify thru 1.5.1. PostgreSQL username and password specified in the docker-compose.yaml file included in its source code. NOTE: the Supplier reports that the Docker configuration does not make PostgreSQL (on TCP port 5432) exposed by default in version 1.0.1 or later.
Published 2025-12-18 · Modified
9.8EPSS 0.009
CVE-2025-3466
Unsanitized Input in langgenius/dify
Published 2025-07-07 · Analyzed
9.8EPSS 0.007
CVE-2024-10252
Code Injection in langgenius/dify
Published 2025-03-20 · Analyzed
8.8EPSS 0.008
CVE-2025-3467
XSS Vulnerability in langgenius/dify
Published 2025-07-07 · Analyzed
8.0EPSS 0.003
CVE-2024-11824
Stored XSS in langgenius/dify
Published 2025-03-20 · Analyzed
7.6EPSS 0.005
CVE-2025-43862
Dify Allows Unauthorized Access and Modification of APP Orchestration
Published 2025-04-25 · Analyzed
7.6EPSS 0.003
CVE-2026-42138
Dify Vulnerable to Stored XSS via SVG-file upload
Published 2026-05-04 · Analyzed
6.9EPSS 0.003
CVE-2025-0184
Server-Side Request Forgery (SSRF) in langgenius/dify
Published 2025-03-20 · Analyzed
6.5EPSS 0.005
CVE-2026-41950
Dify < 1.14.0 Authorization Bypass via File UUID
Published 2026-05-05 · Modified
6.5EPSS 0.005
CVE-2025-32796
Dify Allows Unauthorized APP Enable/Disable via API
Published 2025-04-18 · Analyzed
6.5EPSS 0.004
CVE-2025-32795
Dify Allows Insecure User Role Access Control for APP Editing
Published 2025-04-18 · Analyzed
6.5EPSS 0.003
CVE-2025-32790
Dify Allows Insecure User Role Access Control for APP DSL Exporting
Published 2025-04-18 · Analyzed
6.3EPSS 0.003
CVE-2025-58747
Dify MCP OAuth Flow Vulnerable to XSS
Published 2025-10-17 · Analyzed
6.1EPSS 0.057
CVE-2025-43854
DIFY vulnerable to Clickjacking Attack
Published 2025-04-28 · Analyzed
6.1EPSS 0.002