CVE-2026-5468 describes a Cross-Site Scripting (XSS) vulnerability in Casdoor version 2.356.0, originating from improper handling of arguments in the dangerouslySetInnerHTML function. This flaw allows a remote attacker to inject malicious scripts via formCss/formCssMobile/formSideHtml parameters, requiring user interaction and resulting in a low integrity impact (CVSS 3.5 LOW). Despite public exploit code being available and the vulnerability being on the "Hot List: Active," there is no evidence of active exploitation in the wild (KEV: No). Community discussion and media coverage are currently minimal, and the vendor has not responded to disclosure attempts.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.356.0CPE matchmatch criteria | cpe:2.3:a:casbin:casdoor:2.356.0:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.