CVE-2022-24124High· 7.5▾ MidnightPoC availableThe query API in Casdoor before 1.13.1 has a SQL injection vulnerability related to the field and value parameters, as demonstrated by api/get-organizations.
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 41.3 · likelihood 11.1 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 3 sources. Availability, not in-the-wild use.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
55%
Exploit-DB · 3 GitHub repos · Nuclei ×1 (last check)
The query API in Casdoor before 1.13.1 has a SQL injection vulnerability related to the field and value parameters, as demonstrated by api/get-organizations.
casdoor < 1.13.1Upgrade to a patched release:
casdoor 1.13.1Connected by shared product, vendor, weakness, or advisory.
CVE-2022-38638Critical· 9.1Casdoor v1.97.3 was discovered to contain an arbitrary file write vulnerability via the fullFilePath parameter at /api/upload-resource.
CVE-2026-91998Critical· 9.9Casdoor through 4.4.0 contains an authorization bypass vulnerability in the /api/mcp endpoint that allows attackers with any application's clientId and clientSecret to gain unrestricted access to user administration across all organizati…
CVE-2026-90942Critical· 9.6Casdoor through 4.4.0 fails to properly mask the instance-wide built-in certificate private key in /api/get-certs and /api/get-cert endpoints, allowing organization administrators to retrieve it
CVE-2026-6815Medium· 5.9Casdoor: Arbitrary file write possible through Local File System storage provider
CVE-2026-9094Critical· 9.8Casdoor: GetTokenExchangeToken bypass through lack of cross-organization JWT signature check
CVE-2026-15630Critical· 9.9A non-global organization admin in one tenant can bypass tenant boundaries to delete, create, or modify resources in any other tenant by exploiting a mismatch between authorization (based on ?id=) and action (based on request body).