Affected by GO-2024-3086
and 14 other vulnerabilities
GO-2024-3086: Casdoor has reflected XSS in QrCodePage.js (GHSL-2024-036) in github.com/casdoor/casdoor
GO-2024-3087: Casdoor CORS misconfiguration (GHSL-2024-035) in github.com/casdoor/casdoor
GO-2025-3661: Casdoor SCIM User Creation Endpoint scim.go HandleScim authorization in github.com/casdoor/casdoor
GO-2025-4026: Casdoor is vulnerable to Improper Authorization in github.com/casdoor/casdoor
GO-2026-5509: Casdoor vulnerable to Open Redirect in github.com/casdoor/casdoor
GO-2026-5535: Casdoor vulnerable to SSRF via crafted Webhook URL in github.com/casdoor/casdoor
GO-2026-5697: Casdoor vulnerable to Stored XSS via Application formCss / formSideHtml in github.com/casdoor/casdoor
GO-2026-5892: Casdoor doesn't verify that a JWT used for token exchange is still active in github.com/casdoor/casdoor
GO-2026-5894: Casdoor does not validate the AudienceRestriction element in SAML assertions in github.com/casdoor/casdoor
GO-2026-5895: Casdoor has an authentication bypass in github.com/casdoor/casdoor
GO-2026-5896: Casdoor allows users to bypass configured MFA requirements in github.com/casdoor/casdoor
GO-2026-5898: Casdoor SAML callback handler accepts any well-formed SAMLResponse sent to /api/acs without verifying that it corresponds to an AuthnRequest in github.com/casdoor/casdoor
GO-2026-5899: Casdoor doesn't enforce SAML assertion time bounds in github.com/casdoor/casdoor
GO-2026-5945: Casdoor: Arbitrary file write possible through Local File System storage provider in github.com/casdoor/casdoor
GO-2026-5953: Casdoor: GetTokenExchangeToken bypass through lack of cross-organization JWT signature check in github.com/casdoor/casdoor