Vulnerability index

Browse CVEs

11 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Beego CRITICAL 9.6
CVE-2025-30223

Beego is an open-source web framework for the Go programming language. Prior to 2.3.6, a Cross-Site Scripting (XSS) vulnerability exists in Beego's R…

Fix: 2.3.6+
Fix from $2,300 2025-03-31
Beego HIGH 7.5
CVE-2024-55885

beego is an open-source web framework for the Go programming language. Versions of beego prior to 2.3.4 use MD5 as a hashing algorithm. MD5 is no lon…

Fix: 2.3.4+
Fix from $1,950 2024-12-12
Beego HIGH 8.8
CVE-2024-40464

An issue in beego v.2.2.0 and before allows a remote attacker to escalate privileges via the sendMail function located in beego/core/logs/smtp.go file

Fix: 2.2.1+
Fix from $1,950 2024-07-31
Beego HIGH 8.8
CVE-2024-40465

An issue in beego v.2.2.0 and before allows a remote attacker to escalate privileges via the getCacheFileName function in file.go file

Fix: 2.2.1+
Fix from $1,950 2024-07-31
Beego CRITICAL 9.8
CVE-2022-31836

The leafInfo.match() function in Beego v2.0.3 and below uses path.join() to deal with wildcardvalues which can lead to cross directory risk.

Fix: after 2.0.3
Fix from $2,300 2022-07-05
Beego CRITICAL 9.8
CVE-2022-31259EPSS 22%

The route lookup process in beego before 1.12.9 and 2.x before 2.0.3 allows attackers to bypass access control. When a /p1/p2/:name route is configur…

Fix: after 2.0.2
Fix from $2,300 2022-05-21
Beego CRITICAL 9.8
CVE-2021-30080

An issue was discovered in the route lookup process in beego before 1.12.11 that allows attackers to bypass access control.

Fix: after 2.0.1
Fix from $2,300 2022-04-05
Beego HIGH 7.8
CVE-2021-27116

An issue was discovered in file profile.go in function MemProf in beego through 2.0.2, allows attackers to launch symlink attacks locally.

Fix: after 2.0.2
Fix from $1,950 2022-04-05
Beego HIGH 7.8
CVE-2021-27117

An issue was discovered in file profile.go in function GetCPUProfile in beego through 2.0.2, allows attackers to launch symlink attacks locally.

Fix: after 2.0.2
Fix from $1,950 2022-04-05
Beego MEDIUM 6.1
CVE-2021-39391

Cross Site Scripting (XSS) vulnerability exists in the admin panel in Beego v2.0.1 via the URI path in an HTTP request, which is activated by adminis…

Patch available
Fix from $1,600 2021-09-14
Beego MEDIUM 5.5
CVE-2019-16355

The File Session Manager in Beego 1.10.0 allows local users to read session files because of weak permissions for individual files.

No fix yet
Fix from $1,600 2019-09-16