Skip to content
Noroxi

langgenius records

27 published records for vendor langgenius.

All records

27 records
  • Dify v1.9.1 is vulnerable to Insecure Permissions.

    HighCVSS 7.5Proof of conceptEPSS 30%

    langgenius · difyDec 18, 2025

  • Default credentials in Dify thru 1.5.1.

    CriticalCVSS 9.8No exploitEPSS 1%

    langgenius · difyDec 18, 2025

  • A Cross-Origin Resource Sharing (CORS) misconfiguration vulnerability exists in Dify v1.9.1 in the /console/api/setup endpoint.

    CriticalCVSS 9.1No exploitEPSS 0%

    langgenius · difyDec 18, 2025

  • A Cross-Origin Resource Sharing (CORS) misconfiguration vulnerability exists in Dify v1.9.1 in the /console/api/system-features endpoint.

    CriticalCVSS 9.1No exploitEPSS 0%

    langgenius · difyDec 18, 2025

  • CVE-2025-1796
    35Monitor

    Admin account takeover through weak Pseudo-Random number generator used in generating password reset codes in langgenius/dify

    HighCVSS 8.8No exploitEPSS 1%

    langgenius · difyMar 20, 2025

  • Improper Restriction of Excessive Authentication Attempts in langgenius/dify

    HighCVSS 8.1No exploitEPSS 1%

    langgenius · difyMar 20, 2025

  • Authentication Bypass in langgenius/dify

    HighCVSS 8.1No exploitEPSS 1%

    langgenius · difyMar 20, 2025

  • Stored XSS in langgenius/dify

    HighCVSS 7.6No exploitEPSS 0%

    langgenius · difyMar 20, 2025

  • Dify Allows Unauthorized Access and Modification of APP Orchestration

    HighCVSS 7.6No exploitEPSS 0%

    langgenius · difyApr 25, 2025

  • Code Injection in langgenius/dify

    HighCVSS 7.2No exploitEPSS 1%

    langgenius · difyMar 20, 2025

  • CVE-2025-3466
    28Monitor

    Unsanitized Input in langgenius/dify

    HighCVSS 7.2No exploitEPSS 1%

    langgenius · difyJul 7, 2025

  • Dify Vulnerable to Stored XSS via SVG-file upload

    MediumCVSS 6.9No exploitEPSS 0%

    langgenius · difyMay 4, 2026

  • SSRF in langgenius/dify

    MediumCVSS 6.5No exploitEPSS 1%

    langgenius · difyMar 20, 2025

  • CVE-2025-0184
    26Monitor

    Server-Side Request Forgery (SSRF) in langgenius/dify

    MediumCVSS 6.5Proof of conceptEPSS 1%

    langgenius · difyMar 20, 2025

  • Dify Allows Unauthorized APP Enable/Disable via API

    MediumCVSS 6.5No exploitEPSS 0%

    langgenius · difyApr 18, 2025

  • Dify Allows Insecure User Role Access Control for APP Editing

    MediumCVSS 6.5No exploitEPSS 0%

    langgenius · difyApr 18, 2025

  • Dify < 1.14.0 Authorization Bypass via File UUID

    MediumCVSS 6.0No exploitEPSS 0%

    langgenius · difyMay 5, 2026

  • Dify Has Broken Access Control on Log Message Endpoint Allows Reading of Chats of Others

    MediumCVSS 6.0No exploitEPSS 0%

    langgenius · difySep 25, 2025

  • User Enumeration via Distinct Error Messages in langgenius/dify-web

    MediumCVSS 5.3Proof of conceptEPSS 1%

    langgenius · difyOct 22, 2025

  • Stored XSS in langgenius/dify

    MediumCVSS 5.4No exploitEPSS 0%

    langgenius · difyMar 20, 2025

  • CVE-2025-3467
    21Monitor

    XSS Vulnerability in langgenius/dify

    MediumCVSS 5.4No exploitEPSS 0%

    langgenius · difyJul 7, 2025

  • Dify has XSS vulnerability

    MediumCVSS 5.3No exploitEPSS 0%

    langgenius · difyJun 17, 2025

  • Dify v1.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component controllers.console.remote_files.RemoteFileUpload

    MediumCVSS 4.8No exploitEPSS 0%

    langgenius · difyApr 14, 2025

  • Privilege Escalation in langgenius/dify

    MediumCVSS 4.3No exploitEPSS 0%

    langgenius · difyMar 20, 2025

  • Dify Allows Insecure User Role Access Control for APP DSL Exporting

    MediumCVSS 4.3No exploitEPSS 0%

    langgenius · difyApr 18, 2025