CVE-2026-5468

Source
https://cve.org/CVERecord?id=CVE-2026-5468
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-5468.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-5468
Aliases
Downstream
Related
Published
2026-04-03T13:30:14.547Z
Modified
2026-07-31T18:30:23.203085968Z
Severity
  • 2.0 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
Casdoor dangerouslySetInnerHTML cross site scripting
Details

A security flaw has been discovered in Casdoor 2.356.0. This affects the function dangerouslySetInnerHTML. Performing a manipulation of the argument formCss/formCssMobile/formSideHtml results in cross site scripting. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

Database specific
{
    "cwe_ids": [
        "CWE-79",
        "CWE-94"
    ],
    "cna_assigner": "VulDB",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/5xxx/CVE-2026-5468.json",
    "unresolved_ranges": [
        {
            "source": "AFFECTED_FIELD",
            "extracted_events": [
                {
                    "introduced": "2.356.0"
                },
                {
                    "last_affected": "2.356.0"
                }
            ]
        }
    ]
}
References

Affected packages

Git / github.com/casdoor/casdoor

Affected ranges

Type
GIT
Repo
https://github.com/casdoor/casdoor
Events
Database specific
{
    "source": "CPE_STRING",
    "cpe": "cpe:2.3:a:casbin:casdoor:2.356.0:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "2.356.0"
        },
        {
            "last_affected": "2.356.0"
        }
    ]
}

Affected versions

2.*
2.356.0
v2.*
v2.356.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-5468.json"