Skip to main content

Vendor archive

ruoyi CVEs

Beta · best-effort

59 CVEs tagged to vendor ruoyi16 Critical, 11 High, 18 Medium, 14 Low, 0 Unrated.

CVE-2025-70986

Published Jan 23, 2026

Incorrect access control in the selectDept function of RuoYi v4.8.2 allows unauthorized attackers to arbitrarily access sensitive department data.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-70985

Published Jan 23, 2026

Incorrect access control in the update function of RuoYi v4.8.2 allows unauthorized attackers to arbitrarily modify data outside of their scope.

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-57521

Published Dec 23, 2025

SQL Injection vulnerability in RuoYi v.4.7.9 and before allows a remote attacker to execute arbitrary code via the createTable function in SqlUtil.java.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-14856

Published Dec 18, 2025

A security vulnerability has been detected in y_project RuoYi up to 4.8.1. The affected element is an unknown function of the file /monitor/cache/getnames. Such manipulation of th…

CVSS 2.1 · Low
evidence mentions
5
Buzz score
28.9
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-67342

Published Dec 12, 2025

RuoYi versions 4.8.1 and earlier is affected by a stored XSS vulnerability in the /system/menu/edit endpoint. While the endpoint is protected by an XSS filter, the protection can…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-46175

Published Nov 26, 2025

Ruoyi v4.8.0 is vulnerable to Incorrect Access Control. There is a missing checkUserDataScope permission check in the authRole method of SysUserController.java.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-56396

Published Nov 26, 2025

An issue was discovered in Ruoyi 4.8.1 allowing attackers to gain escalated privileges due to the owning department having higher rights than the active user.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-46174

Published Nov 26, 2025

Ruoyi v4.8.0 vulnerable to Incorrect Access Control. There is a missing checkUserDataScope permission check in the resetPwd Method of SysUserController.java.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-10989

Published Sep 26, 2025

A security flaw has been discovered in yangzongzhuan RuoYi up to 4.8.1. This vulnerability affects unknown code of the file /system/role/authUser/selectAll. Performing manipulatio…

CVSS 2.1 · Low
evidence mentions
4
Buzz score
22.6
Vendor/product tagsBeta · best-effort

CVE-2025-10473

Published Sep 15, 2025

A security flaw has been discovered in yangzongzhuan RuoYi up to 4.8.1. This impacts the function filterKeyword of the file /com/ruoyi/common/utils/sql/SqlUtil.java of the compone…

CVSS 2.1 · Low
evidence mentions
4
Buzz score
27.1
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-10384

Published Sep 13, 2025

A flaw has been found in yangzongzhuan RuoYi up to 4.8.1. Affected by this vulnerability is an unknown functionality of the file /system/role/authUser/cancelAll of the component R…

CVSS 2.1 · Low
evidence mentions
4
Buzz score
22.6
Vendor/product tagsBeta · best-effort

CVE-2025-8847

Published Aug 11, 2025

A vulnerability was found in yangzongzhuan RuoYi up to 4.8.1. Affected by this vulnerability is the function Edit of the file /system/notice/edit. The manipulation of the argument…

CVSS 2.0 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-7907

Published Jul 20, 2025

A vulnerability was found in yangzongzhuan RuoYi up to 4.8.1. It has been classified as problematic. Affected is an unknown function of the file ruoyi-admin/src/main/resources/app…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-7906

Published Jul 20, 2025

A vulnerability was found in yangzongzhuan RuoYi up to 4.8.1 and classified as critical. This issue affects the function uploadFile of the file ruoyi-admin/src/main/java/com/ruoyi…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-7903

Published Jul 20, 2025

A vulnerability classified as problematic was found in yangzongzhuan RuoYi up to 4.8.1. Affected by this vulnerability is an unknown functionality of the component Image Source Ha…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-7902

Published Jul 20, 2025

A vulnerability classified as problematic has been found in yangzongzhuan RuoYi up to 4.8.1. Affected is the function addSave of the file com/ruoyi/web/controller/system/SysNotice…

CVSS 2.0 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-7901

Published Jul 20, 2025

A vulnerability was found in yangzongzhuan RuoYi up to 4.8.1. It has been rated as problematic. This issue affects some unknown processing of the file /swagger-ui/index.html of th…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-4819

Published May 17, 2025

A vulnerability classified as problematic has been found in y_project RuoYi 4.8.0. Affected is an unknown function of the file /monitor/online/batchForceLogout of the component Of…

CVSS 2.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-4537

Published May 11, 2025

A vulnerability was found in yangzongzhuan RuoYi-Vue up to 3.8.9 and classified as problematic. Affected by this issue is some unknown functionality of the file ruoyi-ui/jsencrypt…

CVSS 2.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-28413

Published Apr 7, 2025

An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the SysDictTypeController component

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-28412

Published Apr 7, 2025

An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the /editSave method in SysNoticeController

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-28411

Published Apr 7, 2025

An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the editSave method in /tool/gen/editSave

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-28410

Published Apr 7, 2025

An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the cancelAuthUserAll method does not properly validate whether the requesting user has administrativ…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-28409

Published Apr 7, 2025

An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the add method of the /add/{parentId} endpoint does not properly validate whether the requesting user…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-28408

Published Apr 7, 2025

An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the selectDeptTree method of the /selectDeptTree/{deptId} endpoint does not properly validate the dep…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-25 of 59 CVEsPage 1 of 3