Casdoor has 5 CVEs on record. 3 were published in the last 90 days. The median CVSS is 9.8 (critical), with 4 rated critical. None have a confirmed exploitation report. The most common weakness class is CWE-863 (3). Most affected products: casdoor (3), github.com/casdoor/casdoor (2).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 9.8
- Publish → KEV
- —
- Last 90 days
- 3 prev 2
Worst active — by depth score
CVE-2026-91998Critical· 9.9Casdoor through 4.4.0 contains an authorization bypass vulnerability in the /api/mcp endpoint that allows attackers with any application's clientId and clientSecret to gain unrestricted access to user administration across all organizati…67CVE-2026-15630Critical· 9.9CVE-2026-1563067CVE-2026-90942Critical· 9.6Casdoor through 4.4.0 fails to properly mask the instance-wide built-in certificate private key in /api/get-certs and /api/get-cert endpoints, allowing organization administrators to retrieve it65CVE-2026-9094Critical· 9.8Casdoor: GetTokenExchangeToken bypass through lack of cross-organization JWT signature check54CVE-2026-6815Medium· 5.9Casdoor: Arbitrary file write possible through Local File System storage provider45
Casdoor vulnerabilities
CVEs affecting Casdoor, newest first. Open any entry for full detail, references, and exploit status.
5 CVEsRSS
CVE-2026-91998Critical· 9.9PoCCasdoor through 4.4.0 contains an authorization bypass vulnerability in the /api/mcp endpoint that allows attackers with any application's clientId and clientSecret to gain unrestricted access to user administration across all organizati…
Casdoor through 4.4.0 contains an authorization bypass vulnerability in the /api/mcp endpoint that allows attackers with any application's clientId and clientSecret to gain unrestricted access to user administration across all organizati…
CVE-2026-90942Critical· 9.6PoCCasdoor through 4.4.0 fails to properly mask the instance-wide built-in certificate private key in /api/get-certs and /api/get-cert endpoints, allowing organization administrators to retrieve it
Casdoor through 4.4.0 fails to properly mask the instance-wide built-in certificate private key in /api/get-certs and /api/get-cert endpoints, allowing organization administrators to retrieve it. Attackers can use the exposed private key…
CVE-2026-15630Critical· 9.9PoCCVE-2026-15630
A non-global organization admin in one tenant can bypass tenant boundaries to delete, create, or modify resources in any other tenant by exploiting a mismatch between authorization (based on ?id=) and action (based on request body).
CVE-2026-9094Critical· 9.8Casdoor: GetTokenExchangeToken bypass through lack of cross-organization JWT signature check
Casdoor: GetTokenExchangeToken bypass through lack of cross-organization JWT signature check
CVE-2026-6815Medium· 5.9PoCCasdoor: Arbitrary file write possible through Local File System storage provider
Casdoor: Arbitrary file write possible through Local File System storage provider