dify records
12 published records for vendor dify.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 41.7%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-639 Authorization Bypass Through User-Controlled Key2
- CWE-918 Server-Side Request Forgery (SSRF)2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-284 Improper Access Control1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
The weakness classes this vendor ships most often: where to look.
CWEAll records
12 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
38Monitor | CVE-2026-41948Proof of concept | Dify v1.14.1 Path Traversal via Plugin Daemon Internal API Accessdify · dify · CWE-23 | Critical9.3 | — | 1.9% | May 18, 2026 |
37Monitor | CVE-2026-41947No exploit | Dify < 1.14.2 Authorization Bypass via Trace Configuration Endpointsdify · dify · CWE-639 | Critical9.3 | — | 0.6% | May 18, 2026 |
35Monitor | CVE-2025-0185No exploit | Pandas Query Injection in langgenius/difydify · dify · CWE-94 | High8.8 | — | 1.1% | Mar 20, 2025 |
34Monitor | CVE-2026-61461No exploit | Dify < 1.16.0-rc1 SQL Injection via MyScale Vector Store search_by_full_textdify · dify · CWE-89 | High8.7 | — | 0.5% | Jul 10, 2026 |
33Monitor | CVE-2025-67732No exploit | Dify Vulnerable to Plaintext API Key Exposure via Model Provider Configuration Endpointdify · dify · CWE-200 | High8.4 | — | 0.3% | Jan 5, 2026 |
32Monitor | CVE-2026-41949No exploit | Dify < 1.14.2 Authorization Bypass via File Preview Endpointdify · dify · CWE-639 | High8.2 | — | 0.6% | May 18, 2026 |
30Monitor | CVE-2024-11822No exploit | Server-Side Request Forgery (SSRF) in langgenius/difydify · dify · CWE-918 | High7.5 | — | 0.6% | Mar 20, 2025 |
22Monitor | CVE-2026-28288Proof of concept | Dify has a user enumeration issuedify · dify · CWE-204 | Medium5.5 | — | 0.7% | Feb 27, 2026 |
21Monitor | CVE-2025-56520Proof of concept | Dify v1.6.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component controllers.console.remote_files.RemoteFileUplodify · dify · CWE-918 | Medium5.3 | — | 0.7% | Sep 30, 2025 |
21Monitor | CVE-2026-26023No exploit | Client‑side DOM XSS in the web chat app of Dify when using echartsdify · dify · CWE-79 | Medium5.3 | — | 0.4% | Feb 11, 2026 |
21Monitor | CVE-2026-34082No exploit | Dify has IDOR in deleting someone else's chat conversationdify · dify · CWE-284 | Medium5.3 | — | 0.3% | Apr 20, 2026 |
20Monitor | CVE-2026-21866No exploit | Dify - Stored XSS in chatdify · dify · CWE-79 | Medium5.1 | — | 0.2% | Mar 3, 2026 |
- CVE-2026-4194838Monitor
Dify v1.14.1 Path Traversal via Plugin Daemon Internal API Access
CriticalCVSS 9.3Proof of conceptEPSS 2%dify · difyMay 18, 2026
- CVE-2026-4194737Monitor
Dify < 1.14.2 Authorization Bypass via Trace Configuration Endpoints
CriticalCVSS 9.3No exploitEPSS 1%dify · difyMay 18, 2026
- CVE-2025-018535Monitor
Pandas Query Injection in langgenius/dify
HighCVSS 8.8No exploitEPSS 1%dify · difyMar 20, 2025
- CVE-2026-6146134Monitor
Dify < 1.16.0-rc1 SQL Injection via MyScale Vector Store search_by_full_text
HighCVSS 8.7No exploitEPSS 0%dify · difyJul 10, 2026
- CVE-2025-6773233Monitor
Dify Vulnerable to Plaintext API Key Exposure via Model Provider Configuration Endpoint
HighCVSS 8.4No exploitEPSS 0%dify · difyJan 5, 2026
- CVE-2026-4194932Monitor
Dify < 1.14.2 Authorization Bypass via File Preview Endpoint
HighCVSS 8.2No exploitEPSS 1%dify · difyMay 18, 2026
- CVE-2024-1182230Monitor
Server-Side Request Forgery (SSRF) in langgenius/dify
HighCVSS 7.5No exploitEPSS 1%dify · difyMar 20, 2025
- CVE-2026-2828822Monitor
Dify has a user enumeration issue
MediumCVSS 5.5Proof of conceptEPSS 1%dify · difyFeb 27, 2026
- CVE-2025-5652021Monitor
Dify v1.6.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component controllers.console.remote_files.RemoteFileUplo
MediumCVSS 5.3Proof of conceptEPSS 1%dify · difySep 30, 2025
- CVE-2026-2602321Monitor
Client‑side DOM XSS in the web chat app of Dify when using echarts
MediumCVSS 5.3No exploitEPSS 0%dify · difyFeb 11, 2026
- CVE-2026-3408221Monitor
Dify has IDOR in deleting someone else's chat conversation
MediumCVSS 5.3No exploitEPSS 0%dify · difyApr 20, 2026
- CVE-2026-2186620Monitor
Dify - Stored XSS in chat
MediumCVSS 5.1No exploitEPSS 0%dify · difyMar 3, 2026