Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Dify

First CVE: Mar 20, 2025Active for: 1 yearTotal CVEs: 12
49.4
VTI Score
High

Dify is a modestly represented, widely deployed open-source platform for building and managing large language model applications, where its narrow product footprint belies prominence in the AI/LLM development landscape. Vulnerabilities affecting the platform skew toward serious outcomes, frequently acquire public exploit code, and cluster around web application and integration weaknesses including authorization bypasses, cross-site scripting, server-side request forgery, and improper access control—exposures typical of user-facing application frameworks handling diverse input sources and external service integration. Defenders deploying or embedding this platform should track security updates closely, particularly for authorization and injection-related flaws; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
12
Total CVEs
More Total CVEs than 93% of tracked vendors
6.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 98% of tracked vendors
7.0
Avg CVSS Score
Higher Avg CVSS Score than 50% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Dify over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 20, 2025
16 months ago
Most Recent CVE
Jul 10, 2026
14 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (12 CVEs).

12 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-61461HIGH
Dify before 1.16.0-rc1 contains a SQL injection vulnerability in the MyScale vector store backend that allows attackers to execute arbitrary SQL by supplying unsanitized search par
Jul 10, 20268.839NONO
CVE-2026-41948CRITICAL
Dify version 1.14.1 and prior contain a path traversal vulnerability that allows authenticated users to manipulate requests forwarded to the Plugin Daemon's internal REST API by ex
May 18, 20269.439NONO
CVE-2026-41947CRITICAL
Dify before version 1.14.2 contains an authorization bypass vulnerability that allows authenticated editor users to set and enable trace configurations for any application regardle
May 18, 20269.137NONO
CVE-2026-41949HIGH
Dify before version 1.14.2 contains an authorization bypass vulnerability in the file preview endpoint that allows any authenticated user to read up to 3,000 characters of any uplo
May 18, 20267.531NONO
CVE-2025-56520MEDIUM
Dify v1.6.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component controllers.console.remote_files.RemoteFileUploadApi. A different vulnerability than CV
Sep 30, 20255.331NOYES
CVE-2026-28288MEDIUM
Dify is an open-source LLM app development platform. Prior to 1.9.0, responses from the Dify API to existing and non-existent accounts differ, allowing an attacker to enumerate ema
Feb 27, 20265.330NOYES
CVE-2025-67732MEDIUM
Dify is an open-source LLM app development platform. Prior to version 1.11.0, the API key is exposed in plaintext to the frontend, allowing non-administrator users to view and reus
Jan 5, 20266.525NONO
CVE-2025-0185HIGH
A vulnerability in the Dify Tools' Vanna module of the langgenius/dify repository allows for a Pandas Query Injection in the latest version. The vulnerability occurs in the functio
Mar 20, 20258.824NONO
CVE-2026-21866MEDIUM
Dify is an open-source LLM app development platform. Prior to 1.11.2, Dify is vulnerable to a stored XSS issue when rendering Mermaid diagrams within chats. This occurs because Dif
Mar 3, 20265.421NONO
CVE-2026-26023MEDIUM
Dify is an open-source LLM app development platform. Prior to 1.13.0, a cross site scripting vulnerability has been found in the web application chat frontend when using echarts. U
Feb 11, 20266.121NONO
View all 12 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products12 CVEs
50%
33%
17%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network12 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low12 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None10 (83.3%)
Unknown0 (0.0%)
Required2 (16.7%)
Privileges Required
Low5 (41.7%)
High0 (0.0%)
None7 (58.3%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (12 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
16.7% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Dify.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Dify — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Dify's Products

View all 4 CNAs →

Top CWEs