langgenius/dify
langgenius- Product type
- Other
- Catalog vulnerabilities
- 14
Severity across 14 analyzed records
Verify to analyze this security profile
en
Severity across 14 analyzed records
Verify to analyze this security profile
As of 09/14/2026, within CyStack's analyzed data, langgenius/dify has 0 security vulnerabilities published in the last 90 days. Of these, 0 are rated High or Critical. None of these vulnerabilities is listed in the CISA KEV catalog. CyStack recommends that organizations and individual users remediate applicable vulnerabilities as soon as possible.
CyStack does not yet have sufficient official-source data to identify the latest version of langgenius/dify and determine which vulnerabilities affect that version.
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan| Vulnerability | Exploitation status | Fix | Published | Severity |
|---|---|---|---|---|
CVE-2025-11750User Enumeration via Distinct Error Messages in langgenius/dify-web | Exploitation statusPublic exploit | FixNot confirmed | Published10/22/2025 | SeverityMedium |
CVE-2025-3467XSS Vulnerability in langgenius/dify | Exploitation statusPublic exploit | FixYes | Published07/07/2025 | SeverityHigh |
CVE-2025-3466Unsanitized Input in langgenius/dify | Exploitation statusPublic exploit | FixYes | Published07/07/2025 | SeverityCritical |
CVE-2025-0184Server-Side Request Forgery (SSRF) in langgenius/dify | Exploitation statusPublic exploit | FixYes | Published03/20/2025 | SeverityMedium |
CVE-2024-11850Stored XSS in langgenius/dify | Exploitation statusPublic exploit | FixNot confirmed | Published03/20/2025 | SeverityMedium |
CVE-2024-12776Authentication Bypass in langgenius/dify | Exploitation statusPublic exploit | FixNot confirmed | Published03/20/2025 | SeverityHigh |
CVE-2024-10252Code Injection in langgenius/dify | Exploitation statusPublic exploit | FixYes | Published03/20/2025 | SeverityHigh |
CVE-2024-12039Improper Restriction of Excessive Authentication Attempts in langgenius/dify | Exploitation statusPublic exploit | FixNot confirmed | Published03/20/2025 | SeverityHigh |
CVE-2024-12775SSRF in langgenius/dify | Exploitation statusPublic exploit | FixNot confirmed | Published03/20/2025 | SeverityMedium |
CVE-2024-11822Server-Side Request Forgery (SSRF) in langgenius/dify | Exploitation statusPublic exploit | FixNot confirmed | Published03/20/2025 | SeverityMedium |
CVE-2025-0185Pandas Query Injection in langgenius/dify | Exploitation statusPublic exploit | FixNot confirmed | Published03/20/2025 | SeverityHigh |
CVE-2024-11824Stored XSS in langgenius/dify | Exploitation statusPublic exploit | FixYes | Published03/20/2025 | SeverityMedium |
CVE-2024-11821Privilege Escalation in langgenius/dify | Exploitation statusPublic exploit | FixNot confirmed | Published03/20/2025 | SeverityMedium |
CVE-2025-1796Admin account takeover through weak Pseudo-Random number generator used in generating password reset codes in langgenius/dify | Exploitation statusPublic exploit | FixNot confirmed | Published03/20/2025 | SeverityHigh |