casbin records
12 published records for vendor casbin.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 25%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-552 Files or Directories Accessible to External Parties1
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
12 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
47Plan | CVE-2022-24124Proof of concept | The query API in Casdoor before 1.13.1 has a SQL injection vulnerability related to the field and value parameters, as demonstrated by api/gcasbin · casdoor · CWE-89 | High7.5 | — | 55.3% | Jan 29, 2022 |
36Monitor | CVE-2022-38638No exploit | Casdoor v1.97.3 was discovered to contain an arbitrary file write vulnerability via the fullFilePath parameter at /api/upload-resource.casbin · casdoor · CWE-22 | Critical9.1 | — | 1.2% | Sep 9, 2022 |
35Monitor | CVE-2024-41657No exploit | GHSL-2024-035: Casdoor CORS misconfigurationcasbin · casdoor · CWE-942 | High8.8 | — | 0.8% | Aug 20, 2024 |
32Monitor | CVE-2022-44942No exploit | Casdoor before v1.126.1 was discovered to contain an arbitrary file deletion vulnerability via the uploadFile function.casbin · casdoor · CWE-22 | High8.1 | — | 0.9% | Dec 6, 2022 |
30Monitor | CVE-2024-41264No exploit | An issue discovered in casdoor v1.636.0 allows attackers to obtain sensitive information via the ssh.InsecureIgnoreHostKey() method.casbin · casdoor · CWE-295 | High7.5 | — | 0.5% | Aug 1, 2024 |
27Monitor | CVE-2023-34927Proof of concept | Casdoor v1.331.0 and below was discovered to contain a Cross-Site Request Forgery (CSRF) in the endpoint /api/set-password.casbin · casdoor · CWE-352 | Medium6.5 | — | 3.1% | Jun 22, 2023 |
27Monitor | CVE-2024-5587No exploit | Casdoor Configuration File app.conf file accessCWE-552 | Medium6.9 | — | 0.5% | Jun 2, 2024 |
24Monitor | CVE-2024-41658No exploit | GHSL-2024-036: Reflected XSS in QrCodePage.jscasbin · casdoor · CWE-79 | Medium6.1 | — | 0.4% | Aug 20, 2024 |
23Monitor | CVE-2026-6815Proof of concept | An arbitrary file write vulnerability exists in Casdoor's Local File System storage provider.casbin · casdoor · CWE-22 | Medium5.9 | — | 0.6% | May 11, 2026 |
20Monitor | CVE-2026-5469No exploit | Casdoor Webhook URL server-side request forgerycasbin · casdoor · CWE-918 | Medium5.1 | — | 0.6% | Apr 3, 2026 |
8Monitor | CVE-2026-5467No exploit | Casdoor OAuth Authorization Request redirectcasbin · casdoor · CWE-601 | Low2.1 | — | 0.4% | Apr 3, 2026 |
8Monitor | CVE-2026-5468No exploit | Casdoor dangerouslySetInnerHTML cross site scriptingcasbin · casdoor · CWE-79 | Low2.0 | — | 0.3% | Apr 3, 2026 |
- CVE-2022-2412447Plan
The query API in Casdoor before 1.13.1 has a SQL injection vulnerability related to the field and value parameters, as demonstrated by api/g
HighCVSS 7.5Proof of conceptEPSS 55%casbin · casdoorJan 29, 2022
- CVE-2022-3863836Monitor
Casdoor v1.97.3 was discovered to contain an arbitrary file write vulnerability via the fullFilePath parameter at /api/upload-resource.
CriticalCVSS 9.1No exploitEPSS 1%casbin · casdoorSep 9, 2022
- CVE-2024-4165735Monitor
GHSL-2024-035: Casdoor CORS misconfiguration
HighCVSS 8.8No exploitEPSS 1%casbin · casdoorAug 20, 2024
- CVE-2022-4494232Monitor
Casdoor before v1.126.1 was discovered to contain an arbitrary file deletion vulnerability via the uploadFile function.
HighCVSS 8.1No exploitEPSS 1%casbin · casdoorDec 6, 2022
- CVE-2024-4126430Monitor
An issue discovered in casdoor v1.636.0 allows attackers to obtain sensitive information via the ssh.InsecureIgnoreHostKey() method.
HighCVSS 7.5No exploitEPSS 0%casbin · casdoorAug 1, 2024
- CVE-2023-3492727Monitor
Casdoor v1.331.0 and below was discovered to contain a Cross-Site Request Forgery (CSRF) in the endpoint /api/set-password.
MediumCVSS 6.5Proof of conceptEPSS 3%casbin · casdoorJun 22, 2023
- CVE-2024-558727Monitor
Casdoor Configuration File app.conf file access
MediumCVSS 6.9No exploitEPSS 0%Jun 2, 2024
- CVE-2024-4165824Monitor
GHSL-2024-036: Reflected XSS in QrCodePage.js
MediumCVSS 6.1No exploitEPSS 0%casbin · casdoorAug 20, 2024
- CVE-2026-681523Monitor
An arbitrary file write vulnerability exists in Casdoor's Local File System storage provider.
MediumCVSS 5.9Proof of conceptEPSS 1%casbin · casdoorMay 11, 2026
- CVE-2026-546920Monitor
Casdoor Webhook URL server-side request forgery
MediumCVSS 5.1No exploitEPSS 1%casbin · casdoorApr 3, 2026
- CVE-2026-54678Monitor
Casdoor OAuth Authorization Request redirect
LowCVSS 2.1No exploitEPSS 0%casbin · casdoorApr 3, 2026
- CVE-2026-54688Monitor
Casdoor dangerouslySetInnerHTML cross site scripting
LowCVSS 2.0No exploitEPSS 0%casbin · casdoorApr 3, 2026