lowCVSS 3.5Vulnerability

CVE-2026-5468

A security flaw has been discovered in Casdoor 2.356.0. This affects the function dangerouslySetInnerHTML. Performing a manipulation of the argument formCss/formCssMobile/formSideHtml results in cross site scripting. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

Properties

summary
Casdoor vulnerable to Stored XSS via Application formCss / formSideHtml
severity
low
epss_score
0.00188
cvss_score
3.5
ghsa_published
2026-04-03T15:30:31Z
source_url
https://github.com/advisories/GHSA-w799-7525-rpr6
ghsa_updated
2026-04-10T15:36:40Z
ghsa_id
GHSA-w799-7525-rpr6
cve_id
CVE-2026-5468
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
is_ghsa_only
false
epss_percentile
0.08688

Related Entities (4)

ENRICHED_BY (1)

[Source]FIRST EPSS

REPORTED_BY (1)

[Source]GitHub Advisory Database

AFFECTS (1)

[Software]go/github.com/casdoor/casdoor

HAS_WEAKNESS (1)

[Weakness]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-5468 (CVSS 3.5) — Ninja Signal Threat Intelligence | Ninja Signal