Vulnerabilities
159 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-41950 | Dify before version 1.14.0 contains an authorization bypass vulnerability that allows authenticated users to read the full contents of files uploaded by other u Dify before version 1.14.0 contains an authorization bypass vulnerability that allows authenticated users to read the full contents of files uploaded by other users within the same tenant by supplying an arbitrary file UUID in the files array of a chat-messages request. Attackers can exploit insufficient permission verification in the chat-messages endpoints to access files without ownership validation, bypassing workspace separation and signed URL protections to retrieve sensitive file contents through workflow processing. NVD description · AI analysis pending | 6.0 | <1% | PoC |
| — | |
| CVE-2026-42138 | Dify is an open-source LLM app development platform. Dify is an open-source LLM app development platform. Prior to version 1.13.1, using the method POST /api/files/upload, any unauthenticated user can upload an SVG file with XSS. The method POST /v1/files/upload, which requires authentication through the application API, is also vulnerable. This issue has been patched in version 1.13.1. NVD description · AI analysis pending | 6.9 | <1% | PoC |
| — | |
| CVE-2025-56015 | In GenieACS 1.2.13, an unauthenticated access vulnerability exists in the NBI API endpoint. In GenieACS 1.2.13, an unauthenticated access vulnerability exists in the NBI API endpoint. NVD description · AI analysis pending | 7.5 | <1% | PoC |
| — | |
| CVE-2026-31976 | xygeni-action is the GitHub Action for Xygeni Scanner. xygeni-action is the GitHub Action for Xygeni Scanner. On March 3, 2026, an attacker with access to compromised credentials created a series of pull requests (#46, #47, #48) injecting obfuscated shell code into action.yml. The PRs were blocked by branch protection rules and never merged into the main branch. However, the attacker used the compromised GitHub App credentials to move the mutable v5 tag to point at the malicious commit (4bf1d4e19ad81a3e8d4063755ae0f482dd3baf12) from one of the unmerged PRs. This commit remained in the repository's git object store, and any workflow referencing @v5 would fetch and execute it. This is a supply chain compromise via tag poisoning. Any GitHub Actions workflow referencing xygeni/xygeni-action@v5 during the affected window (approximately March 3–10, 2026) executed a C2 implant that granted the attacker arbitrary command execution on the CI runner for up to 180 seconds per workflow run. NVD description · AI analysis pending | 9.3 | <1% |
| — | ||
| CVE-2019-25355 | gSOAP 2.8 contains a directory traversal vulnerability that allows unauthenticated attackers to access system files by manipulating HTTP path traversal techniqu gSOAP 2.8 contains a directory traversal vulnerability that allows unauthenticated attackers to access system files by manipulating HTTP path traversal techniques. Attackers can retrieve sensitive files like /etc/passwd by sending crafted GET requests with multiple '../' directory traversal sequences. NVD description · AI analysis pending | 8.7 | 1% | PoC |
| — | |
| CVE-2025-56157 | Default credentials in Dify thru 1.5.1. Default credentials in Dify thru 1.5.1. PostgreSQL username and password specified in the docker-compose.yaml file included in its source code. NOTE: the Supplier reports that the Docker configuration does not make PostgreSQL (on TCP port 5432) exposed by default in version 1.0.1 or later. NVD description · AI analysis pending | 9.8 group max | <1% | PoC |
| — | |
| CVE-2025-11750 | In langgenius/dify-web version 1.6.0, the authentication mechanism reveals the existence of user accounts by returning different error messages for non-existent In langgenius/dify-web version 1.6.0, the authentication mechanism reveals the existence of user accounts by returning different error messages for non-existent and existing accounts. Specifically, when a login or registration attempt is made with a non-existent username or email, the system responds with a message such as "account not found." Conversely, when the username or email exists but the password is incorrect, a different error message is returned. This discrepancy allows an attacker to enumerate valid user accounts by analyzing the error responses, potentially facilitating targeted social engineering, brute force, or credential stuffing attacks. NVD description · AI analysis pending | 5.3 | <1% | PoC |
| — | |
| CVE-2025-58747 | Dify is an LLM application development platform. Dify is an LLM application development platform. In Dify versions through 1.9.1, the MCP OAuth component is vulnerable to cross-site scripting when a victim connects to an attacker-controlled remote MCP server. The vulnerability exists in the OAuth flow implementation where the authorization_url provided by a remote MCP server is directly passed to window.open without validation or sanitization. An attacker can craft a malicious MCP server that returns a JavaScript URI (such as javascript:alert(1)) in the authorization_url field, which is then executed when the victim attempts to connect to the MCP server. This allows the attacker to execute arbitrary JavaScript in the context of the Dify application. NVD description · AI analysis pending | 2.0 | 5% | PoC |
| — | |
| CVE-2025-59422 | Dify is an open-source LLM app development platform. Dify is an open-source LLM app development platform. In version 1.8.1, a broken access control vulnerability on the /console/api/apps/ chat-messages?conversation_id= &limit=10 endpoint allows users in the same workspace to read chat messages of other users. A regular user is able to read the query data and the filename of the admins and probably other users chats, if they know the conversation_id. This impacts the confidentiality of chats. This issue has been patched in version 1.9.0. NVD description · AI analysis pending | 6.0 | <1% | PoC |
| — | |
| CVE-2025-3466 +1 in the same advisory: …3467 | langgenius/dify versions 1.1.0 to 1.1.2 are vulnerable to unsanitized input in the code node, allowing execution of arbitrary code with full root permissions. langgenius/dify versions 1.1.0 to 1.1.2 are vulnerable to unsanitized input in the code node, allowing execution of arbitrary code with full root permissions. The vulnerability arises from the ability to override global functions in JavaScript, such as parseInt, before sandbox security restrictions are imposed. This can lead to unauthorized access to secret keys, internal network servers, and lateral movement within dify.ai. The issue is resolved in version 1.1.3. NVD description · AI analysis pending | 7.2 group max | <1% | PoC |
| — | |
| CVE-2025-2940 | The Ninja Tables – Easy Data Table Builder plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5.0.18 via th The Ninja Tables – Easy Data Table Builder plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5.0.18 via the args[url] parameter. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services. NVD description · AI analysis pending | 7.2 | <1% |
| — | ||
| CVE-2025-34035 | An OS command injection vulnerability exists in EnGenius EnShare Cloud Service version 1.4.11 and earlier. An OS command injection vulnerability exists in EnGenius EnShare Cloud Service version 1.4.11 and earlier. The usbinteract.cgi script fails to properly sanitize user input passed to the path parameter, allowing unauthenticated remote attackers to inject arbitrary shell commands. The injected commands are executed with root privileges, leading to full system compromise. Exploitation evidence was observed by the Shadowserver Foundation on 2024-12-05 UTC. NVD description · AI analysis pending | 10.0 | 13% | PoC ×3 |
| — | |
| CVE-2025-49149 | Dify is an open-source LLM app development platform. Dify is an open-source LLM app development platform. In version 1.2.0, there is insufficient filtering of user input by web applications. Attackers can use website vulnerabilities to inject malicious script code into web pages. This may result in a cross-site scripting (XSS) attack when a user browses these web pages. At time of posting, there is no known patched version. NVD description · AI analysis pending | 5.3 | <1% | PoC |
| — | |
| CVE-2025-2939 | The Ninja Tables – Easy Data Table Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 5.0.18 via deseriali The Ninja Tables – Easy Data Table Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 5.0.18 via deserialization of untrusted input from the args[callback] parameter . This makes it possible for unauthenticated attackers to inject a PHP Object. The additional presence of a POP chain allows attackers to execute arbitrary functions, though it does not allow user supplied parameters only single functions can be called so the impact is limited. NVD description · AI analysis pending | 5.6 | <1% |
| — | ||
| CVE-2025-28371 | EnGenius ENH500 AP 2T2R V3.0 FW3.7.22 is vulnerable to Incorrect Access Control via the password change function. EnGenius ENH500 AP 2T2R V3.0 FW3.7.22 is vulnerable to Incorrect Access Control via the password change function. The device fails to validate the current password, allowing an attacker to submit a password change request with an invalid current password and set a new password. NVD description · AI analysis pending | 6.5 | <1% | PoC |
| — | |
| CVE-2024-13845 | The Gravity Forms WebHooks plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.6.0 via the 'process_feed' The Gravity Forms WebHooks plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.6.0 via the 'process_feed' method of the GF_Webhooks class This makes it possible for authenticated attackers, with Administrator-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services. NVD description · AI analysis pending | 5.5 | <1% |
| — | ||
| CVE-2025-43854 | DIFY is an open-source LLM app development platform. DIFY is an open-source LLM app development platform. Prior to version 1.3.0, a clickjacking vulnerability was found in the default setup of the DIFY application, allowing malicious actors to trick users into clicking on elements of the web page without their knowledge or consent. This can lead to unauthorized actions being performed, potentially compromising the security and privacy of users. This issue has been fixed in version 1.3.0. NVD description · AI analysis pending | 2.3 | <1% |
| — | ||
| CVE-2025-43862 | Dify is an open-source LLM app development platform. Dify is an open-source LLM app development platform. Prior to version 0.6.12, a normal user is able to access and modify APP orchestration, even though the web UI of APP orchestration is not presented for a normal user. This access control flaw allows non-admin users to make unauthorized access and changes on the APPSs. This issue has been patched in version 0.6.12. A workaround for this vulnerability involves updating the the access control mechanisms to enforce stricter user role permissions and implementing role-based access controls (RBAC) to ensure that only users with admin privileges can access Orchestration of the APPs. NVD description · AI analysis pending | 7.6 | <1% | PoC |
| — | |
| CVE-2025-32796 | Dify is an open-source LLM app development platform. Dify is an open-source LLM app development platform. Prior to version 0.6.12, a vulnerability was identified in the DIFY where normal users can enable or disable apps through the API, even though the web UI button for this action is disabled and normal users are not permitted to make such changes. This access control flaw allows non-admin users to make unauthorized changes, which can disrupt the functionality and availability of the APPS. This issue has been patched in version 0.6.12. A workaround for this vulnerability involves updating the API access control mechanisms to enforce stricter user role permissions and implementing role-based access controls (RBAC) to ensure that only users with admin privileges can send enable or disable requests for apps. NVD description · AI analysis pending | 6.5 group max | <1% | PoC |
| — | |
| CVE-2025-29720 | Dify v1.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component controllers.console.remote_files.RemoteFileUploadApi. Dify v1.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component controllers.console.remote_files.RemoteFileUploadApi. NVD description · AI analysis pending | 4.8 | <1% | PoC |
| — | |
| CVE-2025-1796 | A vulnerability in langgenius/dify v0.10.1 allows an attacker to take over any account, including administrator accounts, by exploiting a weak pseudo-random num A vulnerability in langgenius/dify v0.10.1 allows an attacker to take over any account, including administrator accounts, by exploiting a weak pseudo-random number generator (PRNG) used for generating password reset codes. The application uses `random.randint` for this purpose, which is not suitable for cryptographic use and can be cracked. An attacker with access to workflow tools can extract the PRNG output and predict future password reset codes, leading to a complete compromise of the application. NVD description · AI analysis pending | 8.8 group max | <1% | PoC |
| — | |
| CVE-2024-13568 | The Fluent Support – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and i The Fluent Support – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.8.5 via the 'fluent-support' directory. This makes it possible for unauthenticated attackers to extract sensitive data stored insecurely in the /wp-content/uploads/fluent-support directory which can contain file attachments included in support tickets. NVD description · AI analysis pending | 7.5 | <1% |
| — | ||
| CVE-2024-12772 | The Ninja Tables WordPress plugin before 5.0.17 does not sanitize and escape a parameter before outputting it back in the page when importing a CSV, leading to The Ninja Tables WordPress plugin before 5.0.17 does not sanitize and escape a parameter before outputting it back in the page when importing a CSV, leading to a Cross Site Scripting vulnerability. NVD description · AI analysis pending | 5.4 | <1% | PoC |
| — | |
| CVE-2024-31976 | EnGenius EWS356-FIR 1.1.30 and earlier devices allow a remote attacker to execute arbitrary OS commands via the Controller connectivity parameter. EnGenius EWS356-FIR 1.1.30 and earlier devices allow a remote attacker to execute arbitrary OS commands via the Controller connectivity parameter. NVD description · AI analysis pending | 8.0 | <1% |
| — | ||
| CVE-2024-11652 | Command injection in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT AP firmware EnGenius firmware for the ENH1350EXT, ENS500-AC and ENS620EXT outdoor access points, in versions up to and including the 20241118 (2024-11-18) build, contains a command-injection flaw (CWE-74/CWE-77) in the web management interface at /admin/sn_package/sn_https. A remote attacker who can reach that endpoint and holds high-privilege (administrative) credentials, per the CVSS 4.0 PR:H metric, can submit a manipulated https_enable parameter to inject operating-system commands on the device. Successful exploitation yields remote command execution, although the CVSS 4.0 impact metrics rate the resulting effect on confidentiality, integrity and availability as low. Any organization running these three EnGenius AP models with a reachable management interface is affected, with internet-exposed or remote-management-enabled deployments at greatest risk. A proof-of-concept exploit has already been published, EPSS assigns a 30.2% probability of exploitation within 30 days (98th percentile), the issue is not yet in CISA KEV, and the vendor was notified early but did not respond, so no fixed firmware is confirmed in the available data. Do: Because the vendor did not respond to the disclosure and no fixed firmware version appears in the available data, check EnGenius support channels for updated firmware for these three models and apply it when released. Until then, restrict access to the web management interface (/admin) to trusted networks or VPN rather than exposing it to the internet, and ensure strong administrator credentials are in use. Review device or reverse-proxy access logs for requests to /admin/sn_package/sn_https with unexpected https_enable values as indicators of probing or exploitation. | 5.1 | 30% | PoC |
| moderate~1,000-10,000 affected devices (total deployed units likely in the low tens of thousands; internet-exposed admin interfaces likely a smaller subset) | |
| CVE-2024-36061 | EnGenius EWS356-FIT devices through 1.1.30 allow blind OS command injection. EnGenius EWS356-FIT devices through 1.1.30 allow blind OS command injection. This allows an attacker to execute arbitrary OS commands via shell metacharacters to the Ping and Speed Test utilities. NVD description · AI analysis pending | 9.8 | 1% |
| — | ||
| CVE-2024-47302 | Missing Authorization vulnerability in Shahjahan Jewel Fluent Support fluent-support allows Exploiting Incorrectly Configured Access Control Security Levels.Thi Missing Authorization vulnerability in Shahjahan Jewel Fluent Support fluent-support allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Fluent Support: from n/a through <= 1.8.0. NVD description · AI analysis pending | 9.8 | <1% |
| — | ||
| CVE-2024-31975 | EnGenius EWS356-Fit devices through 1.1.30 allow a remote attacker to conduct stored XSS attacks via the Wi-Fi SSID parameters. EnGenius EWS356-Fit devices through 1.1.30 allow a remote attacker to conduct stored XSS attacks via the Wi-Fi SSID parameters. JavaScript embedded into a vulnerable field is executed when the user clicks the SSID field's corresponding EDIT button. NVD description · AI analysis pending | 4.8 | <1% |
| — |