Critical
Low
Medium
CVE-2025-11750
Overview
In langgenius/dify-web version 1.6.0, the authentication mechanism reveals the existence of user accounts by returning different error messages for non-existent and existing accounts. Specifically, when a login or registration attempt is made with a non-existent username or email, the system respond...
Critical
Low
Medium
No items found.