langgenius records
27 published records for vendor langgenius.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 37%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')6
- CWE-284 Improper Access Control6
- CWE-918 Server-Side Request Forgery (SSRF)3
- CWE-346 Origin Validation Error2
- CWE-307 Improper Restriction of Excessive Authentication Attempts1
- CWE-338 Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)1
The weakness classes this vendor ships most often: where to look.
CWEAll records
27 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2025-63387Proof of concept | Dify v1.9.1 is vulnerable to Insecure Permissions.langgenius · dify · CWE-284 | High7.5 | — | 29.9% | Dec 18, 2025 |
39Monitor | CVE-2025-56157No exploit | Default credentials in Dify thru 1.5.1.langgenius · dify · CWE-798 | Critical9.8 | — | 0.9% | Dec 18, 2025 |
36Monitor | CVE-2025-63386No exploit | A Cross-Origin Resource Sharing (CORS) misconfiguration vulnerability exists in Dify v1.9.1 in the /console/api/setup endpoint.langgenius · dify · CWE-346 | Critical9.1 | — | 0.2% | Dec 18, 2025 |
36Monitor | CVE-2025-63388No exploit | A Cross-Origin Resource Sharing (CORS) misconfiguration vulnerability exists in Dify v1.9.1 in the /console/api/system-features endpoint.langgenius · dify · CWE-346 | Critical9.1 | — | 0.2% | Dec 18, 2025 |
35Monitor | CVE-2025-1796No exploit | Admin account takeover through weak Pseudo-Random number generator used in generating password reset codes in langgenius/difylanggenius · dify · CWE-338 | High8.8 | — | 0.6% | Mar 20, 2025 |
32Monitor | CVE-2024-12039No exploit | Improper Restriction of Excessive Authentication Attempts in langgenius/difylanggenius · dify · CWE-307 | High8.1 | — | 0.7% | Mar 20, 2025 |
32Monitor | CVE-2024-12776No exploit | Authentication Bypass in langgenius/difylanggenius · dify · CWE-305 | High8.1 | — | 0.7% | Mar 20, 2025 |
30Monitor | CVE-2024-11824No exploit | Stored XSS in langgenius/difylanggenius · dify · CWE-79 | High7.6 | — | 0.5% | Mar 20, 2025 |
30Monitor | CVE-2025-43862No exploit | Dify Allows Unauthorized Access and Modification of APP Orchestrationlanggenius · dify · CWE-284 | High7.6 | — | 0.3% | Apr 25, 2025 |
28Monitor | CVE-2024-10252No exploit | Code Injection in langgenius/difylanggenius · dify · CWE-94 | High7.2 | — | 0.8% | Mar 20, 2025 |
28Monitor | CVE-2025-3466No exploit | Unsanitized Input in langgenius/difylanggenius · dify · CWE-1100 | High7.2 | — | 0.8% | Jul 7, 2025 |
27Monitor | CVE-2026-42138No exploit | Dify Vulnerable to Stored XSS via SVG-file uploadlanggenius · dify · CWE-79 | Medium6.9 | — | 0.3% | May 4, 2026 |
26Monitor | CVE-2024-12775No exploit | SSRF in langgenius/difylanggenius · dify · CWE-918 | Medium6.5 | — | 0.6% | Mar 20, 2025 |
26Monitor | CVE-2025-0184Proof of concept | Server-Side Request Forgery (SSRF) in langgenius/difylanggenius · dify · CWE-918 | Medium6.5 | — | 0.5% | Mar 20, 2025 |
26Monitor | CVE-2025-32796No exploit | Dify Allows Unauthorized APP Enable/Disable via APIlanggenius · dify · CWE-284 | Medium6.5 | — | 0.4% | Apr 18, 2025 |
26Monitor | CVE-2025-32795No exploit | Dify Allows Insecure User Role Access Control for APP Editinglanggenius · dify · CWE-284 | Medium6.5 | — | 0.3% | Apr 18, 2025 |
24Monitor | CVE-2026-41950No exploit | Dify < 1.14.0 Authorization Bypass via File UUIDlanggenius · dify · CWE-639 | Medium6.0 | — | 0.5% | May 5, 2026 |
24Monitor | CVE-2025-59422No exploit | Dify Has Broken Access Control on Log Message Endpoint Allows Reading of Chats of Otherslanggenius · dify · CWE-284 | Medium6.0 | — | 0.2% | Sep 25, 2025 |
21Monitor | CVE-2025-11750Proof of concept | User Enumeration via Distinct Error Messages in langgenius/dify-weblanggenius · dify · CWE-544 | Medium5.3 | — | 0.7% | Oct 22, 2025 |
21Monitor | CVE-2024-11850No exploit | Stored XSS in langgenius/difylanggenius · dify · CWE-79 | Medium5.4 | — | 0.4% | Mar 20, 2025 |
21Monitor | CVE-2025-3467No exploit | XSS Vulnerability in langgenius/difylanggenius · dify · CWE-79 | Medium5.4 | — | 0.4% | Jul 7, 2025 |
21Monitor | CVE-2025-49149No exploit | Dify has XSS vulnerabilitylanggenius · dify · CWE-79 | Medium5.3 | — | 0.3% | Jun 17, 2025 |
19Monitor | CVE-2025-29720No exploit | Dify v1.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component controllers.console.remote_files.RemoteFileUploadlanggenius · dify · CWE-918 | Medium4.8 | — | 0.2% | Apr 14, 2025 |
17Monitor | CVE-2024-11821No exploit | Privilege Escalation in langgenius/difylanggenius · dify · CWE-250 | Medium4.3 | — | 0.5% | Mar 20, 2025 |
17Monitor | CVE-2025-32790No exploit | Dify Allows Insecure User Role Access Control for APP DSL Exportinglanggenius · dify · CWE-284 | Medium4.3 | — | 0.3% | Apr 18, 2025 |
- CVE-2025-6338739Monitor
Dify v1.9.1 is vulnerable to Insecure Permissions.
HighCVSS 7.5Proof of conceptEPSS 30%langgenius · difyDec 18, 2025
- CVE-2025-5615739Monitor
Default credentials in Dify thru 1.5.1.
CriticalCVSS 9.8No exploitEPSS 1%langgenius · difyDec 18, 2025
- CVE-2025-6338636Monitor
A Cross-Origin Resource Sharing (CORS) misconfiguration vulnerability exists in Dify v1.9.1 in the /console/api/setup endpoint.
CriticalCVSS 9.1No exploitEPSS 0%langgenius · difyDec 18, 2025
- CVE-2025-6338836Monitor
A Cross-Origin Resource Sharing (CORS) misconfiguration vulnerability exists in Dify v1.9.1 in the /console/api/system-features endpoint.
CriticalCVSS 9.1No exploitEPSS 0%langgenius · difyDec 18, 2025
- CVE-2025-179635Monitor
Admin account takeover through weak Pseudo-Random number generator used in generating password reset codes in langgenius/dify
HighCVSS 8.8No exploitEPSS 1%langgenius · difyMar 20, 2025
- CVE-2024-1203932Monitor
Improper Restriction of Excessive Authentication Attempts in langgenius/dify
HighCVSS 8.1No exploitEPSS 1%langgenius · difyMar 20, 2025
- CVE-2024-1277632Monitor
Authentication Bypass in langgenius/dify
HighCVSS 8.1No exploitEPSS 1%langgenius · difyMar 20, 2025
- CVE-2024-1182430Monitor
Stored XSS in langgenius/dify
HighCVSS 7.6No exploitEPSS 0%langgenius · difyMar 20, 2025
- CVE-2025-4386230Monitor
Dify Allows Unauthorized Access and Modification of APP Orchestration
HighCVSS 7.6No exploitEPSS 0%langgenius · difyApr 25, 2025
- CVE-2024-1025228Monitor
Code Injection in langgenius/dify
HighCVSS 7.2No exploitEPSS 1%langgenius · difyMar 20, 2025
- CVE-2025-346628Monitor
Unsanitized Input in langgenius/dify
HighCVSS 7.2No exploitEPSS 1%langgenius · difyJul 7, 2025
- CVE-2026-4213827Monitor
Dify Vulnerable to Stored XSS via SVG-file upload
MediumCVSS 6.9No exploitEPSS 0%langgenius · difyMay 4, 2026
- CVE-2024-1277526Monitor
SSRF in langgenius/dify
MediumCVSS 6.5No exploitEPSS 1%langgenius · difyMar 20, 2025
- CVE-2025-018426Monitor
Server-Side Request Forgery (SSRF) in langgenius/dify
MediumCVSS 6.5Proof of conceptEPSS 1%langgenius · difyMar 20, 2025
- CVE-2025-3279626Monitor
Dify Allows Unauthorized APP Enable/Disable via API
MediumCVSS 6.5No exploitEPSS 0%langgenius · difyApr 18, 2025
- CVE-2025-3279526Monitor
Dify Allows Insecure User Role Access Control for APP Editing
MediumCVSS 6.5No exploitEPSS 0%langgenius · difyApr 18, 2025
- CVE-2026-4195024Monitor
Dify < 1.14.0 Authorization Bypass via File UUID
MediumCVSS 6.0No exploitEPSS 0%langgenius · difyMay 5, 2026
- CVE-2025-5942224Monitor
Dify Has Broken Access Control on Log Message Endpoint Allows Reading of Chats of Others
MediumCVSS 6.0No exploitEPSS 0%langgenius · difySep 25, 2025
- CVE-2025-1175021Monitor
User Enumeration via Distinct Error Messages in langgenius/dify-web
MediumCVSS 5.3Proof of conceptEPSS 1%langgenius · difyOct 22, 2025
- CVE-2024-1185021Monitor
Stored XSS in langgenius/dify
MediumCVSS 5.4No exploitEPSS 0%langgenius · difyMar 20, 2025
- CVE-2025-346721Monitor
XSS Vulnerability in langgenius/dify
MediumCVSS 5.4No exploitEPSS 0%langgenius · difyJul 7, 2025
- CVE-2025-4914921Monitor
Dify has XSS vulnerability
MediumCVSS 5.3No exploitEPSS 0%langgenius · difyJun 17, 2025
- CVE-2025-2972019Monitor
Dify v1.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component controllers.console.remote_files.RemoteFileUpload
MediumCVSS 4.8No exploitEPSS 0%langgenius · difyApr 14, 2025
- CVE-2024-1182117Monitor
Privilege Escalation in langgenius/dify
MediumCVSS 4.3No exploitEPSS 0%langgenius · difyMar 20, 2025
- CVE-2025-3279017Monitor
Dify Allows Insecure User Role Access Control for APP DSL Exporting
MediumCVSS 4.3No exploitEPSS 0%langgenius · difyApr 18, 2025