Casdoor
Vendor:
First CVE: Jan 29, 2022 · Active for 4 years
11
Total CVEs
More Total CVEs than 90% of tracked products
2.8
Avg CVEs / Year
Higher CVE frequency than 78% of tracked products
7.1
Avg CVSS
Higher Avg CVSS than 46% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Casdoor over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jan 29, 2022
4 years ago
Most Recent CVE
May 11, 2026
78 days ago
CVE Severity & Scoring
Casdoor11 CVEs
45%
45%
9%
All CVEs353,240 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (9.1%)
Network10 (90.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low11 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None6 (54.5%)
Unknown0 (0.0%)
Required5 (45.5%)
Privileges Required
Low2 (18.2%)
High1 (9.1%)
None8 (72.7%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-24124HIGH The query API in Casdoor before 1.13.1 has a SQL injection vulnerability related to the field and value parameters, as demonstrated by api/get-organizations. | Jan 29, 2022 | 7.5 | 75 | NO | YES |
CVE-2026-6815MEDIUM An arbitrary file write vulnerability exists in Casdoor's Local File System storage provider. Due to insufficient path sanitization, an authenticated attacker with administrative p | May 11, 2026 | 5.9 | 35 | NO | YES |
CVE-2023-34927MEDIUM Casdoor v1.331.0 and below was discovered to contain a Cross-Site Request Forgery (CSRF) in the endpoint /api/set-password. This vulnerability allows attackers to arbitrarily chang | Jun 22, 2023 | 6.5 | 29 | NO | YES |
CVE-2022-38638CRITICAL Casdoor v1.97.3 was discovered to contain an arbitrary file write vulnerability via the fullFilePath parameter at /api/upload-resource. | Sep 9, 2022 | 9.1 | 28 | NO | NO |
CVE-2026-5469HIGH A weakness has been identified in Casdoor 2.356.0. This vulnerability affects unknown code of the component Webhook URL Handler. Executing a manipulation can lead to server-side re | Apr 3, 2026 | 7.2 | 26 | NO | NO |
CVE-2022-44942HIGH Casdoor before v1.126.1 was discovered to contain an arbitrary file deletion vulnerability via the uploadFile function. | Dec 7, 2022 | 8.1 | 26 | NO | NO |
CVE-2024-41657HIGH Casdoor is a UI-first Identity and Access Management (IAM) / Single-Sign-On (SSO) platform. In Casdoor 1.577.0 and earlier, a logic vulnerability exists in the beego filter CorsFil | Aug 20, 2024 | 8.8 | 25 | NO | NO |
CVE-2026-5467MEDIUM A vulnerability was identified in Casdoor 2.356.0. Affected by this issue is some unknown functionality of the component OAuth Authorization Request Handler. Such manipulation of t | Apr 3, 2026 | 6.1 | 24 | NO | NO |
CVE-2026-5468MEDIUM A security flaw has been discovered in Casdoor 2.356.0. This affects the function dangerouslySetInnerHTML. Performing a manipulation of the argument formCss/formCssMobile/formSideH | Apr 3, 2026 | 5.4 | 22 | NO | NO |
CVE-2024-41264HIGH An issue discovered in casdoor v1.636.0 allows attackers to obtain sensitive information via the ssh.InsecureIgnoreHostKey() method. | Aug 1, 2024 | 7.5 | 21 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (11 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
9.1% of CVEs· 97th percentile
ExploitDB
3 CVEs
27.3% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (11 CVEs).
Media Mentions
Signals from CVEs in this product scope (11 CVEs).
Top CNAs Publishing CVEs For Casdoor
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.356.0 | 3 | 6.2 | 0.3% | 0 | 0 |
| 1.97.3 | 1 | 9.1 | 1.0% | 0 | 0 |
| 1.636.0 | 1 | 7.5 | 0.5% | 0 | 0 |