Home/Product/beego
Product

beego

12 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-30223
< 2.3.6
Beego is an open-source web framework for the Go programming language. Prior to 2.3.6, a Cross-Site Scripting (XSS) vulnerability
9.3CRITICAL
CVE-2024-55885
< 2.3.4
beego is an open-source web framework for the Go programming language. Versions of beego prior to 2.3.4 use MD5 as a hashing algor
7.5HIGH
CVE-2024-40465
< 2.2.1
An issue in beego v.2.2.0 and before allows a remote attacker to escalate privileges via the getCacheFileName function in file.go
8.8HIGH
CVE-2024-40464
< 2.2.1
An issue in beego v.2.2.0 and before allows a remote attacker to escalate privileges via the sendMail function located in beego/co
8.8HIGH
CVE-2022-31836
<= 2.0.3
The leafInfo.match() function in Beego v2.0.3 and below uses path.join() to deal with wildcardvalues which can lead to cross direc
9.8CRITICAL
CVE-2022-31259
<= 1.12.4
The route lookup process in beego before 1.12.9 and 2.x before 2.0.3 allows attackers to bypass access control. When a /p1/p2/:nam
9.8CRITICAL
CVE-2021-30080
<= 2.0.1
An issue was discovered in the route lookup process in beego before 1.12.11 that allows attackers to bypass access control.
9.8CRITICAL
CVE-2021-27117
<= 2.0.2
An issue was discovered in file profile.go in function GetCPUProfile in beego through 2.0.2, allows attackers to launch symlink at
7.8HIGH
CVE-2021-27116
<= 2.0.2
An issue was discovered in file profile.go in function MemProf in beego through 2.0.2, allows attackers to launch symlink attacks
7.8HIGH
CVE-2021-39391
all versions
Cross Site Scripting (XSS) vulnerability exists in the admin panel in Beego v2.0.1 via the URI path in an HTTP request, which is a
6.1MEDIUM
CVE-2019-16355
all versions
The File Session Manager in Beego 1.10.0 allows local users to read session files because of weak permissions for individual files
5.5MEDIUM
CVE-2019-16354
all versions
The File Session Manager in Beego 1.10.0 allows local users to read session files because there is a race condition involving file
4.7MEDIUM
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin