Daloradius is a modestly represented open-source RADIUS management and administration web interface that serves authentication and access-control infrastructure, typically deployed in enterprise network and ISP environments. Its vulnerability profile concentrates on the application-layer attack surface, with recurrent weaknesses spanning cross-site scripting, cross-site request forgery, code injection, insecure file-resource handling, and permission-assignment flaws that are characteristic of web-facing administrative interfaces. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Daloradius over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-0048HIGH Code Injection in GitHub repository lirantal/daloradius prior to master-branch. | Jan 4, 2023 | 8.8 | 37 | NO | NO |
CVE-2022-23475HIGH daloRADIUS is an open source RADIUS web management application. daloRadius 1.3 and prior are vulnerable to a combination cross site scripting (XSS) and cross site request forgery ( | Dec 6, 2022 | 8.8 | 28 | NO | NO |
CVE-2023-0046HIGH Improper Restriction of Names for Files and Other Resources in GitHub repository lirantal/daloradius prior to master-branch. | Jan 4, 2023 | 7.2 | 25 | NO | NO |
CVE-2022-4366HIGH Missing Authorization in GitHub repository lirantal/daloradius prior to master branch. | Dec 8, 2022 | 7.5 | 25 | NO | NO |
CVE-2023-0338MEDIUM Cross-site Scripting (XSS) - Reflected in GitHub repository lirantal/daloradius prior to master-branch. | Jan 17, 2023 | 6.1 | 22 | NO | NO |
CVE-2023-0337MEDIUM Cross-site Scripting (XSS) - Reflected in GitHub repository lirantal/daloradius prior to master-branch. | Jan 17, 2023 | 6.1 | 22 | NO | NO |
CVE-2022-4630MEDIUM Sensitive Cookie Without 'HttpOnly' Flag in GitHub repository lirantal/daloradius prior to master. | Dec 21, 2022 | 5.3 | 20 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Daloradius.
Media articles that mention a CVE ID that affects a product developed by Daloradius — matched by CVE ID, not by vendor name.