VYPR

Casdoor

by Casdoor

Source repositories

CVEs (27)

  • CVE-2025-61524HigOct 8, 2025
    risk 0.40cvss 7.2epss 0.01

    An issue in the permission verification module and organization/application editing interface in Casdoor v2.26.0 and before, and fixed in v.2.63.0, allows remote authenticated administrators of any organization within the system to bypass the system's permission verification…

  • CVE-2024-41658MedAug 20, 2024
    risk 0.40cvss 6.1epss 0.00

    Casdoor is a UI-first Identity and Access Management (IAM) / Single-Sign-On (SSO) platform. In Casdoor 1.577.0 and earlier, he purchase URL that is created to generate a WechatPay QR code is vulnerable to reflected XSS. When purchasing an item through casdoor, the product page…

  • CVE-2026-9091MedMay 28, 2026
    risk 0.34cvss 5.3epss 0.00

    Casdoor versions 2.362.0 and earlier contain a logic flaw in the social‑login binding flow that allows users to bypass configured MFA requirements. The binding‑rule code path in controllers/auth.go calls HandleLoggedIn directly without invoking checkMfaEnable. Any user…

  • CVE-2024-5587MedJun 2, 2024
    risk 0.34cvss 5.3epss 0.00

    A vulnerability was found in Casdoor up to 1.335.0. It has been classified as problematic. Affected is an unknown function of the file /conf/app.conf of the component Configuration File Handler. The manipulation leads to files or directories accessible. It is possible to launch…

  • CVE-2026-5469MedApr 3, 2026
    risk 0.31cvss 4.7epss 0.00

    A weakness has been identified in Casdoor 2.356.0. This vulnerability affects unknown code of the component Webhook URL Handler. Executing a manipulation can lead to server-side request forgery. The attack can be launched remotely. The vendor was contacted early about this…

  • CVE-2026-5467MedApr 3, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was identified in Casdoor 2.356.0. Affected by this issue is some unknown functionality of the component OAuth Authorization Request Handler. Such manipulation of the argument redirect_uri leads to open redirect. It is possible to launch the attack remotely. The…

  • CVE-2026-5468LowApr 3, 2026
    risk 0.23cvss 3.5epss 0.00

    A security flaw has been discovered in Casdoor 2.356.0. This affects the function dangerouslySetInnerHTML. Performing a manipulation of the argument formCss/formCssMobile/formSideHtml results in cross site scripting. The attack can be initiated remotely. The exploit has been…

Page 2 of 2