Langgenius
17 CVEs tracked since 2025. Since Mar 2025, none of them reached CISA KEV.
Langgenius CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2025-03 | 11 | 0 |
| 2025-04 | 6 | 0 |
Products
The products that kept showing up in Langgenius's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Langgenius.
- CVE-2026-85022langgenius dify WebApp Sign-In mail-and-password-auth.tsx router.replace cross site scripting3.5
- CVE-2026-85021langgenius dify Splash Layout splash.tsx router.replace cross site scripting4.3
- CVE-2026-18632langgenius dify Jinja2 jinja2_transformer.py jinja2.Template special elements used in a template engine6.3
- CVE-2026-18266Dify AI Workflow oauth_redirect_url Open Redirect Vulnerability5.4
- CVE-2026-61461Dify < 1.16.0-rc1 SQL Injection via MyScale Vector Store search_by_full_text8.8
- CVE-2026-41949Dify < 1.14.2 Authorization Bypass via File Preview Endpoint5.9
- CVE-2026-41948Dify v1.14.1 Path Traversal via Plugin Daemon Internal API Access9.4
- CVE-2026-41947Dify < 1.14.2 Authorization Bypass via Trace Configuration Endpoints9.1
- CVE-2026-41950Dify < 1.14.0 Authorization Bypass via File UUID6.5
- CVE-2026-42138Dify Vulnerable to Stored XSS via SVG-file upload6.1
- CVE-2026-34082Dify has IDOR in deleting someone else's chat conversation4.3
- CVE-2026-6619langgenius dify ImagePreview image-preview.tsx openInNewTab cross site scripting3.5
- CVE-2026-6618langgenius dify ApiBasedToolSchemaParser parser.py parse_openai_plugin_json_to_tool_bundle server-side request forgery6.3
- CVE-2026-6617langgenius dify ApiToolManageService api_tools_manage_service.py get_api_tool_provider_remote_schema server-side request forgery6.3
- CVE-2026-21866Dify - Stored XSS in chat5.4
The record
- Peak rank
- #90 in Mar 2025
- Busiest month shown
- Mar 2025, 11 CVEs
- Months with a KEV entry
- 0 since Mar 2025
- Monthly snapshots
- 2 since 2025