Casdoor

Vendor:

First CVE: Jan 29, 2022 · Active for 4 years

11
Total CVEs
More Total CVEs than 90% of tracked products
2.8
Avg CVEs / Year
Higher CVE frequency than 78% of tracked products
7.1
Avg CVSS
Higher Avg CVSS than 46% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Casdoor over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 29, 2022
4 years ago
Most Recent CVE
May 11, 2026
78 days ago

CVE Severity & Scoring

Casdoor11 CVEs
All CVEs353,240 CVEs
MediumHighCritical
Attack Vector
Local1 (9.1%)
Network10 (90.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low11 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None6 (54.5%)
Unknown0 (0.0%)
Required5 (45.5%)
Privileges Required
Low2 (18.2%)
High1 (9.1%)
None8 (72.7%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (11 CVEs).

11 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The query API in Casdoor before 1.13.1 has a SQL injection vulnerability related to the field and value parameters, as demonstrated by api/get-organizations.
Jan 29, 20227.575NOYES
An arbitrary file write vulnerability exists in Casdoor's Local File System storage provider. Due to insufficient path sanitization, an authenticated attacker with administrative p
May 11, 20265.935NOYES
Casdoor v1.331.0 and below was discovered to contain a Cross-Site Request Forgery (CSRF) in the endpoint /api/set-password. This vulnerability allows attackers to arbitrarily chang
Jun 22, 20236.529NOYES
Casdoor v1.97.3 was discovered to contain an arbitrary file write vulnerability via the fullFilePath parameter at /api/upload-resource.
Sep 9, 20229.128NONO
A weakness has been identified in Casdoor 2.356.0. This vulnerability affects unknown code of the component Webhook URL Handler. Executing a manipulation can lead to server-side re
Apr 3, 20267.226NONO
Casdoor before v1.126.1 was discovered to contain an arbitrary file deletion vulnerability via the uploadFile function.
Dec 7, 20228.126NONO
Casdoor is a UI-first Identity and Access Management (IAM) / Single-Sign-On (SSO) platform. In Casdoor 1.577.0 and earlier, a logic vulnerability exists in the beego filter CorsFil
Aug 20, 20248.825NONO
A vulnerability was identified in Casdoor 2.356.0. Affected by this issue is some unknown functionality of the component OAuth Authorization Request Handler. Such manipulation of t
Apr 3, 20266.124NONO
A security flaw has been discovered in Casdoor 2.356.0. This affects the function dangerouslySetInnerHTML. Performing a manipulation of the argument formCss/formCssMobile/formSideH
Apr 3, 20265.422NONO
An issue discovered in casdoor v1.636.0 allows attackers to obtain sensitive information via the ssh.InsecureIgnoreHostKey() method.
Aug 1, 20247.521NONO

Exploit Exposure

Signals from CVEs in this product scope (11 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
9.1% of CVEs· 97th percentile
ExploitDB
3 CVEs
27.3% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (11 CVEs).

Media Mentions

Signals from CVEs in this product scope (11 CVEs).

Top CNAs Publishing CVEs For Casdoor

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
2.356.036.20.3%00
1.97.319.11.0%00
1.636.017.50.5%00