Skip to content
Noroxi

dify records

12 published records for vendor dify.

All records

12 records
  • Dify v1.14.1 Path Traversal via Plugin Daemon Internal API Access

    CriticalCVSS 9.3Proof of conceptEPSS 2%

    dify · difyMay 18, 2026

  • Dify < 1.14.2 Authorization Bypass via Trace Configuration Endpoints

    CriticalCVSS 9.3No exploitEPSS 1%

    dify · difyMay 18, 2026

  • CVE-2025-0185
    35Monitor

    Pandas Query Injection in langgenius/dify

    HighCVSS 8.8No exploitEPSS 1%

    dify · difyMar 20, 2025

  • Dify < 1.16.0-rc1 SQL Injection via MyScale Vector Store search_by_full_text

    HighCVSS 8.7No exploitEPSS 0%

    dify · difyJul 10, 2026

  • Dify Vulnerable to Plaintext API Key Exposure via Model Provider Configuration Endpoint

    HighCVSS 8.4No exploitEPSS 0%

    dify · difyJan 5, 2026

  • Dify < 1.14.2 Authorization Bypass via File Preview Endpoint

    HighCVSS 8.2No exploitEPSS 1%

    dify · difyMay 18, 2026

  • Server-Side Request Forgery (SSRF) in langgenius/dify

    HighCVSS 7.5No exploitEPSS 1%

    dify · difyMar 20, 2025

  • Dify has a user enumeration issue

    MediumCVSS 5.5Proof of conceptEPSS 1%

    dify · difyFeb 27, 2026

  • Dify v1.6.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component controllers.console.remote_files.RemoteFileUplo

    MediumCVSS 5.3Proof of conceptEPSS 1%

    dify · difySep 30, 2025

  • Client‑side DOM XSS in the web chat app of Dify when using echarts

    MediumCVSS 5.3No exploitEPSS 0%

    dify · difyFeb 11, 2026

  • Dify has IDOR in deleting someone else's chat conversation

    MediumCVSS 5.3No exploitEPSS 0%

    dify · difyApr 20, 2026

  • Dify - Stored XSS in chat

    MediumCVSS 5.1No exploitEPSS 0%

    dify · difyMar 3, 2026