Vulnerability index

Browse CVEs

11 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Dify HIGH 8.8
CVE-2026-61461

Dify before 1.16.0-rc1 contains a SQL injection vulnerability in the MyScale vector store backend that allows attackers to execute arbitrary SQL by s…

Fix: 1.16.0+
Fix from $1,950 2026-07-10
Dify HIGH 7.5
CVE-2026-41949

Dify before version 1.14.2 contains an authorization bypass vulnerability in the file preview endpoint that allows any authenticated user to read up …

Fix: after 1.14.1
Fix from $1,950 2026-05-18
Dify CRITICAL 9.4
CVE-2026-41948EPSS 7%

Dify version 1.14.1 and prior contain a path traversal vulnerability that allows authenticated users to manipulate requests forwarded to the Plugin D…

Fix: after 1.14.1
Fix from $2,300 2026-05-18
Dify CRITICAL 9.1
CVE-2026-41947EPSS 6%

Dify before version 1.14.2 contains an authorization bypass vulnerability that allows authenticated editor users to set and enable trace configuratio…

Fix: after 1.14.1
Fix from $2,300 2026-05-18
Dify MEDIUM 5.4
CVE-2026-21866

Dify is an open-source LLM app development platform. Prior to 1.11.2, Dify is vulnerable to a stored XSS issue when rendering Mermaid diagrams within…

Fix: 1.11.2+
Fix from $1,600 2026-03-03
Dify MEDIUM 5.3
CVE-2026-28288

Dify is an open-source LLM app development platform. Prior to 1.9.0, responses from the Dify API to existing and non-existent accounts differ, allowi…

Fix: 1.9.0+
Fix from $1,600 2026-02-27
Dify MEDIUM 6.1
CVE-2026-26023

Dify is an open-source LLM app development platform. Prior to 1.13.0, a cross site scripting vulnerability has been found in the web application chat…

Fix: after 1.11.4
Fix from $1,600 2026-02-11
Dify MEDIUM 6.5
CVE-2025-67732

Dify is an open-source LLM app development platform. Prior to version 1.11.0, the API key is exposed in plaintext to the frontend, allowing non-admin…

Fix: 1.11.0+
Fix from $1,600 2026-01-05
Dify MEDIUM 5.3
CVE-2025-56520

Dify v1.6.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component controllers.console.remote_files.RemoteFileUploadApi. A …

No fix yet
Fix from $1,600 2025-09-30
Dify HIGH 8.8
CVE-2025-0185

A vulnerability in the Dify Tools' Vanna module of the langgenius/dify repository allows for a Pandas Query Injection in the latest version. The vuln…

No fix yet
Fix from $1,950 2025-03-20
Dify HIGH 7.5
CVE-2024-11822

langgenius/dify version 0.9.1 contains a Server-Side Request Forgery (SSRF) vulnerability. The vulnerability exists due to improper handling of the a…

No fix yet
Fix from $1,950 2025-03-20