Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 345 respecto a la semana anterior
Críticas / altas1316▼ 9 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 273 respecto a la semana anterior
27 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.38% | — | Casbin CasdoorAI | 5/10/2026 | 5/10/2026 | A vulnerability was detected in Casdoor up to 3.161.1. Affected is the function ApiFilter of the file routers/authz_filter.go of the component API Endpoint. Performing a manipulation results in missing authentication. The attack can be initiated remotely. The exploit is now public and may be used. The vendor was… | |
| Aplazada | Crítica (9.4) | 0.59% | — | Casbin CasdoorAI | 15/9/2026 | 23/9/2026 | Casdoor through 4.4.0 contains an authorization bypass vulnerability in the /api/mcp endpoint that allows attackers with any application's clientId and clientSecret to gain unrestricted access to user administration across all organizations. Attackers can enumerate user records including password salts and email… | |
| Aplazada | Crítica (9.3) | 0.28% | — | Casbin CasdoorAI | 14/9/2026 | 23/9/2026 | Casdoor through 4.4.0 fails to properly mask the instance-wide built-in certificate private key in /api/get-certs and /api/get-cert endpoints, allowing organization administrators to retrieve it. Attackers can use the exposed private key to forge JWT tokens for any user in any organization, including global… | |
| Aplazada | Media (5.5) | 0.69% | — | Casbin CasdoorAI | 1/9/2026 | 3/9/2026 | A vulnerability has been found in Casdoor up to 4.0.0. This affects an unknown function of the file controllers/resource.go of the component upload-resource API. Such manipulation leads to missing authentication. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be… | |
| Aplazada | Crítica (9.1) | 0.21% | — | Casbin CasdoorAI | 28/5/2026 | 17/6/2026 | In Casdoor versions 2.362.0 and earlier, the SAML callback handler in controllers/auth.go accepts any well-formed SAMLResponse sent to /api/acs without verifying that it corresponds to an AuthnRequest previously issued by Casdoor. Additionally, if an administrator disables or deletes an IdP (Identity Provider) after a… | |
| Aplazada | Crítica (9.8) | 0.48% | — | Casbin CasdoorAI | 28/5/2026 | 17/6/2026 | Casdoor versions 2.362.0 and earlier do not verify that a JWT used for token exchange is still active. The GetTokenExchangeToken() function in object/token_oauth.go validates the JWT signature and parses its claims, but never queries the Token table to verify whether the subject token has been revoked or invalidated.… | |
| Aplazada | Alta (7.5) | 0.43% | — | Russellhaering Gosaml2AICasbin CasdoorAI | 28/5/2026 | 17/6/2026 | Casdoor versions 2.362.0 and earlier do not enforce SAML assertion time bounds. The gosaml2 library reports all time-validation results, including NotOnOrAfter and NotBefore, in the assertionInfo.WarningInfo field. However, ParseSamlResponse() never reads this field, meaning that time bounds are computed by the… | |
| Aplazada | Alta (8.1) | 0.37% | — | Casbin CasdoorAI | 28/5/2026 | 17/6/2026 | Casdoor versions 2.362.0 and earlier map SAML assertions to user sessions without replay protection. The ParseSamlResponse() function in object/saml_sp.go calls sp.RetrieveAssertionInfo() and immediately maps the result to a user session. There is no assertion ID cache, OneTimeUse condition enforcement, or replay… | |
| Aplazada | Crítica (9.8) | 0.48% | — | Casbin CasdoorAI | 28/5/2026 | 17/6/2026 | Casdoor versions 2.362.0 and earlier contain a vulnerability enabling cross-organization token exchange. The GetTokenExchangeToken function in object/token_oauth.go validates JWT signatures but does not verify that the token's user belongs to the same organization as the target application. This can result in… | |
| Aplazada | Crítica (9.8) | 0.48% | — | Casbin CasdoorAI | 28/5/2026 | 17/6/2026 | In Casdoor versions 2.362.0 and earlier, the SAML service provider implementation does not validate the AudienceRestriction element in SAML assertions. The buildSp function in object/saml_sp.go never sets AudienceURI on the gosaml2 SAMLServiceProvider struct and never inspects WarningInfo.NotInAudience. This allows… | |
| Aplazada | Crítica (9.1) | 0.40% | — | Casbin CasdoorAI | 28/5/2026 | 17/6/2026 | Casdoor versions 2.362.0 and earlier contain a vulnerability involving unverified email binding that may enable account takeover. The getExistUserByBindingRule function matches users by email without checking the email_verified claim from upstream providers; the idp.UserInfo struct does not even include a… | |
| Aplazada | Media (5.3) | 0.36% | — | Casbin CasdoorAI | 28/5/2026 | 17/6/2026 | Casdoor versions 2.362.0 and earlier contain a logic flaw in the social‑login binding flow that allows users to bypass configured MFA requirements. The binding‑rule code path in controllers/auth.go calls HandleLoggedIn directly without invoking checkMfaEnable. Any user authenticating via this path is logged in without… | |
| Aplazada | Crítica (9.1) | 0.20% | — | Casbin CasdoorAI | 28/5/2026 | 17/6/2026 | Casdoor versions 2.362.0 and earlier contain a vulnerability that allows an attacker to bypass authentication by supplying an arbitrary signing certificate. The buildSpCertificateStore function extracts the X.509 certificate directly from the incoming SAMLResponse instead of using the trusted pre-configured Identity… | |
| Analizada | Media (5.9) | 0.59% | — | Casbin Casdoor | 11/5/2026 | 17/6/2026 | An arbitrary file write vulnerability exists in Casdoor's Local File System storage provider. Due to insufficient path sanitization, an authenticated attacker with administrative privileges can perform a Path Traversal attack to create or overwrite arbitrary files anywhere on the host filesystem, bypassing the… | |
| Analizada | Media (5.1) | 0.57% | — | Casbin Casdoor | 3/4/2026 | 24/7/2026 | A weakness has been identified in Casdoor 2.356.0. This vulnerability affects unknown code of the component Webhook URL Handler. Executing a manipulation can lead to server-side request forgery. The attack can be launched remotely. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Analizada | Baja (2) | 0.32% | — | Casbin Casdoor | 3/4/2026 | 24/7/2026 | A security flaw has been discovered in Casdoor 2.356.0. This affects the function dangerouslySetInnerHTML. Performing a manipulation of the argument formCss/formCssMobile/formSideHtml results in cross site scripting. The attack can be initiated remotely. The exploit has been released to the public and may be used for… | |
| Analizada | Baja (2.1) | 0.43% | — | Casbin Casdoor | 3/4/2026 | 24/7/2026 | A vulnerability was identified in Casdoor 2.356.0. Affected by this issue is some unknown functionality of the component OAuth Authorization Request Handler. Such manipulation of the argument redirect_uri leads to open redirect. It is possible to launch the attack remotely. The exploit is publicly available and might… | |
| Aplazada | Alta (7.2) | 0.66% | — | Casbin CasdoorAI | 8/10/2025 | 5/7/2026 | An issue in the permission verification module and organization/application editing interface in Casdoor v2.26.0 and before, and fixed in v.2.63.0, allows remote authenticated administrators of any organization within the system to bypass the system's permission verification mechanism by directly concatenating URLs… | |
| Aplazada | Media (6.9) | 1.8% | — | Casbin CasdoorAI | 2/5/2025 | 17/6/2026 | A vulnerability classified as critical was found in Casdoor up to 1.811.0. This vulnerability affects the function HandleScim of the file controllers/scim.go of the component SCIM User Creation Endpoint. The manipulation leads to authorization bypass. The attack can be initiated remotely. Upgrading to version 1.812.0… | |
| Analizada | Media (6.1) | 0.45% | — | Casbin Casdoor | 20/8/2024 | 17/6/2026 | Casdoor is a UI-first Identity and Access Management (IAM) / Single-Sign-On (SSO) platform. In Casdoor 1.577.0 and earlier, he purchase URL that is created to generate a WechatPay QR code is vulnerable to reflected XSS. When purchasing an item through casdoor, the product page allows you to pay via wechat pay. When… | |
| Analizada | Alta (8.8) | 0.79% | — | Casbin Casdoor | 20/8/2024 | 17/6/2026 | Casdoor is a UI-first Identity and Access Management (IAM) / Single-Sign-On (SSO) platform. In Casdoor 1.577.0 and earlier, a logic vulnerability exists in the beego filter CorsFilter that allows any website to make cross domain requests to Casdoor as the logged in user. Due to the a logic error in checking only for a… | |
| Analizada | Alta (7.5) | 0.46% | — | Casbin Casdoor | 1/8/2024 | 17/6/2026 | An issue discovered in casdoor v1.636.0 allows attackers to obtain sensitive information via the ssh.InsecureIgnoreHostKey() method. | |
| Aplazada | Media (6.9) | 0.47% | — | Casbin CasdoorAI | 2/6/2024 | 17/6/2026 | A vulnerability was found in Casdoor up to 1.335.0. It has been classified as problematic. Affected is an unknown function of the file /conf/app.conf of the component Configuration File Handler. The manipulation leads to files or directories accessible. It is possible to launch the attack remotely. The exploit has… | |
| Modificada | Media (6.5) | 3.1% | — | Casbin Casdoor | 22/6/2023 | 17/6/2026 | Casdoor v1.331.0 and below was discovered to contain a Cross-Site Request Forgery (CSRF) in the endpoint /api/set-password. This vulnerability allows attackers to arbitrarily change the victim user's password via supplying a crafted URL. | |
| Modificada | Alta (8.1) | 0.87% | — | Casbin Casdoor | 7/12/2022 | 17/6/2026 | Casdoor before v1.126.1 was discovered to contain an arbitrary file deletion vulnerability via the uploadFile function. |