vciy

CVEs we hold for Langgenius

Records whose assigning authority named Langgenius as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-85022langgenius dify WebApp Sign-In mail-and-password-auth.tsx router.replace cross site scriptinglanggenius dify
CVE-2026-85021langgenius dify Splash Layout splash.tsx router.replace cross site scriptinglanggenius dify
CVE-2026-6619langgenius dify ImagePreview image-preview.tsx openInNewTab cross site scriptinglanggenius dify
CVE-2026-6618langgenius dify ApiBasedToolSchemaParser parser.py parse_openai_plugin_json_to_tool_bundle server-side request forgerylanggenius dify
CVE-2026-6617langgenius dify ApiToolManageService api_tools_manage_service.py get_api_tool_provider_remote_schema server-side…langgenius dify
CVE-2026-61461Dify < 1.16.0-rc1 SQL Injection via MyScale Vector Store search_by_full_textlanggenius dify
CVE-2026-42138Dify Vulnerable to Stored XSS via SVG-file uploadlanggenius dify
CVE-2026-41950Dify < 1.14.0 Authorization Bypass via File UUIDlanggenius dify
CVE-2026-41949Dify < 1.14.2 Authorization Bypass via File Preview Endpointlanggenius dify
CVE-2026-41948Dify v1.14.1 Path Traversal via Plugin Daemon Internal API Accesslanggenius dify
CVE-2026-41947Dify < 1.14.2 Authorization Bypass via Trace Configuration Endpointslanggenius dify
CVE-2026-34082Dify has IDOR in deleting someone else's chat conversationlanggenius dify
CVE-2026-28288Dify has a user enumeration issuelanggenius dify
CVE-2026-26023Client‑side DOM XSS in the web chat app of Dify when using echartslanggenius dify
CVE-2026-21866Dify - Stored XSS in chatlanggenius dify
CVE-2026-18632langgenius dify Jinja2 jinja2_transformer.py jinja2.Template special elements used in a template enginelanggenius dify
CVE-2026-18266Dify AI Workflow oauth_redirect_url Open Redirect VulnerabilityLangGenius Dify
CVE-2025-67732Dify Vulnerable to Plaintext API Key Exposure via Model Provider Configuration Endpointlanggenius dify
CVE-2025-59422Dify Has Broken Access Control on Log Message Endpoint Allows Reading of Chats of Otherslanggenius dify
CVE-2025-58747Dify MCP OAuth Flow Vulnerable to XSSlanggenius dify
CVE-2025-49149Dify has XSS vulnerabilitylanggenius dify
CVE-2025-43862Dify Allows Unauthorized Access and Modification of APP Orchestrationlanggenius dify
CVE-2025-43854DIFY vulnerable to Clickjacking Attacklanggenius dify
CVE-2025-3467XSS Vulnerability in langgenius/difylanggenius/dify
CVE-2025-3466Unsanitized Input in langgenius/difylanggenius/dify
CVE-2025-32796Dify Allows Unauthorized APP Enable/Disable via APIlanggenius dify
CVE-2025-32795Dify Allows Insecure User Role Access Control for APP Editinglanggenius dify
CVE-2025-32790Dify Allows Insecure User Role Access Control for APP DSL Exportinglanggenius dify
CVE-2025-1796Admin account takeover through weak Pseudo-Random number generator used in generating password reset codes in…langgenius/dify
CVE-2025-11750User Enumeration via Distinct Error Messages in langgenius/dify-weblanggenius/dify
CVE-2025-0185Pandas Query Injection in langgenius/difylanggenius/dify
CVE-2025-0184Server-Side Request Forgery (SSRF) in langgenius/difylanggenius/dify
CVE-2024-12776Authentication Bypass in langgenius/difylanggenius/dify
CVE-2024-12775SSRF in langgenius/difylanggenius/dify
CVE-2024-12039Improper Restriction of Excessive Authentication Attempts in langgenius/difylanggenius/dify
CVE-2024-11850Stored XSS in langgenius/difylanggenius/dify
CVE-2024-11824Stored XSS in langgenius/difylanggenius/dify
CVE-2024-11822Server-Side Request Forgery (SSRF) in langgenius/difylanggenius/dify
CVE-2024-11821Privilege Escalation in langgenius/difylanggenius/dify
CVE-2024-10252Code Injection in langgenius/difylanggenius/dify

40 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.