Vulnerability index

Browse CVEs

23 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Dify MEDIUM 6.5
CVE-2026-41950

Dify before version 1.14.0 contains an authorization bypass vulnerability that allows authenticated users to read the full contents of files uploaded…

Fix: 1.14.0+
Fix from $1,600 2026-05-05
Dify MEDIUM 6.1
CVE-2026-42138

Dify is an open-source LLM app development platform. Prior to version 1.13.1, using the method POST /api/files/upload, any unauthenticated user can u…

Fix: 1.13.1+
Fix from $1,600 2026-05-04
Dify HIGH 7.5
CVE-2025-63387EPSS 30%

Dify v1.9.1 is vulnerable to Insecure Permissions. An unauthenticated attacker can directly send HTTP GET requests to the /console/api/system-feature…

Patch available
Fix from $1,950 2025-12-18
Dify CRITICAL 9.8
CVE-2025-56157

Default credentials in Dify thru 1.5.1. PostgreSQL username and password specified in the docker-compose.yaml file included in its source code. NOTE:…

Fix: after 1.5.1
Fix from $2,300 2025-12-18
Dify CRITICAL 9.1
CVE-2025-63386

A Cross-Origin Resource Sharing (CORS) misconfiguration vulnerability exists in Dify v1.9.1 in the /console/api/setup endpoint. The endpoint implemen…

Patch available
Fix from $2,300 2025-12-18
Dify CRITICAL 9.1
CVE-2025-63388

A Cross-Origin Resource Sharing (CORS) misconfiguration vulnerability exists in Dify v1.9.1 in the /console/api/system-features endpoint. The endpoin…

Mitigation only
Fix from $2,300 2025-12-18
Dify MEDIUM 5.3
CVE-2025-11750

In langgenius/dify-web version 1.6.0, the authentication mechanism reveals the existence of user accounts by returning different error messages for n…

No fix yet
Fix from $1,600 2025-10-22
Dify MEDIUM 6.1
CVE-2025-58747EPSS 5%

Dify is an LLM application development platform. In Dify versions through 1.9.1, the MCP OAuth component is vulnerable to cross-site scripting when a…

Fix: 1.9.2+
Fix from $1,600 2025-10-17
Dify HIGH 7.2
CVE-2025-3466

langgenius/dify versions 1.1.0 to 1.1.2 are vulnerable to unsanitized input in the code node, allowing execution of arbitrary code with full root per…

Fix: 1.1.3+
Fix from $1,950 2025-07-07
Dify MEDIUM 5.4
CVE-2025-3467

An XSS vulnerability exists in langgenius/dify versions prior to 1.1.3, specifically affecting Firefox browsers. This vulnerability allows an attacke…

Fix: 1.1.3+
Fix from $1,600 2025-07-07
Dify MEDIUM 6.1
CVE-2025-49149

Dify is an open-source LLM app development platform. In version 1.2.0, there is insufficient filtering of user input by web applications. Attackers c…

No fix yet
Fix from $1,600 2025-06-17
Dify MEDIUM 6.1
CVE-2025-43854

DIFY is an open-source LLM app development platform. Prior to version 1.3.0, a clickjacking vulnerability was found in the default setup of the DIFY …

Fix: after 0.6.8
Fix from $1,600 2025-04-28
Dify HIGH 7.6
CVE-2025-43862

Dify is an open-source LLM app development platform. Prior to version 0.6.12, a normal user is able to access and modify APP orchestration, even thou…

Fix: 0.6.12+
Fix from $1,950 2025-04-25
Dify MEDIUM 6.5
CVE-2025-32795

Dify is an open-source LLM app development platform. Prior to version 0.6.12, a vulnerability was identified in the DIFY where normal users are impro…

Fix: 0.6.12+
Fix from $1,600 2025-04-18
Dify MEDIUM 6.5
CVE-2025-32796

Dify is an open-source LLM app development platform. Prior to version 0.6.12, a vulnerability was identified in the DIFY where normal users can enabl…

Fix: after 0.6.8
Fix from $1,600 2025-04-18
Dify HIGH 8.8
CVE-2025-1796

A vulnerability in langgenius/dify v0.10.1 allows an attacker to take over any account, including administrator accounts, by exploiting a weak pseudo…

No fix yet
Fix from $1,950 2025-03-20
Dify MEDIUM 6.5
CVE-2025-0184

A Server-Side Request Forgery (SSRF) vulnerability was identified in langgenius/dify version 0.10.2. The vulnerability occurs in the 'Create Knowledg…

Fix: 0.11.0+
Fix from $1,600 2025-03-20
Dify HIGH 8.1
CVE-2024-12776

In langgenius/dify v0.10.1, the `/forgot-password/resets` endpoint does not verify the password reset code, allowing an attacker to reset the passwor…

No fix yet
Fix from $1,950 2025-03-20
Dify MEDIUM 6.5
CVE-2024-12775

langgenius/dify version 0.10.1 contains a Server-Side Request Forgery (SSRF) vulnerability in the test functionality for the Create Custom Tool optio…

No fix yet
Fix from $1,600 2025-03-20
Dify HIGH 8.1
CVE-2024-12039

langgenius/dify version v0.10.1 contains a vulnerability where there are no limits applied to the number of code guess attempts for password reset. T…

No fix yet
Fix from $1,950 2025-03-20
Dify HIGH 7.6
CVE-2024-11824

A stored cross-site scripting (XSS) vulnerability exists in langgenius/dify version latest, specifically in the chat log functionality. The vulnerabi…

Fix: 0.12.1+
Fix from $1,950 2025-03-20
Dify MEDIUM 5.4
CVE-2024-11850

A stored cross-site scripting (XSS) vulnerability exists in the latest version of langgenius/dify. The vulnerability is due to improper validation an…

No fix yet
Fix from $1,600 2025-03-20
Dify HIGH 7.2
CVE-2024-10252

A vulnerability in langgenius/dify versions <=v0.9.1 allows for code injection via internal SSRF requests in the Dify sandbox service. This vulnerabi…

Fix: after 0.9.1
Fix from $1,950 2025-03-20