VYPR

ruoyi-vue-pro

by YunaiV

CVEs (6)

  • CVE-2025-10988MedSep 26, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was identified in YunaiV ruoyi-vue-pro up to 2025.09. This affects an unknown part of the file /crm/business/transfer. Such manipulation leads to improper authorization. It is possible to launch the attack remotely. The exploit is publicly available and might be…

  • CVE-2025-10278MedSep 12, 2025
    risk 0.41cvss 6.3epss 0.00

    A flaw has been found in YunaiV ruoyi-vue-pro up to 2025.09. Impacted is an unknown function of the file /crm/contact/transfer. This manipulation of the argument ids/newOwnerUserId causes improper authorization. The attack is possible to be carried out remotely. The exploit has…

  • CVE-2025-10276MedSep 12, 2025
    risk 0.41cvss 6.3epss 0.00

    A security vulnerability has been detected in YunaiV ruoyi-vue-pro up to 2025.09. This vulnerability affects unknown code of the file /crm/contract/transfer. The manipulation of the argument id/newOwnerUserId leads to improper authorization. Remote exploitation of the attack is…

  • CVE-2026-13528HigJun 29, 2026
    risk 0.40cvss 7.3epss 0.01

    A vulnerability was found in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.04-jdk8-SNAPSHOT. The impacted element is the function generateUploadPath of the file yudao-module-infra/src/main/java/cn/iocoder/yudao/module/infra/service/file/FileServiceImpl.java of the component…

  • CVE-2026-57950HigJun 29, 2026
    risk 0.00cvss 8.1epss 0.00

    ruoyi-vue-pro through 2026.05, fixed in commit 5d1fd70 contains a broken access control vulnerability in ErpSaleOrderController that allows attackers with erp:sale-out permissions to gain unauthorized access to sale order operations by exploiting an incorrect permission…

  • CVE-2026-57949MedJun 29, 2026
    risk 0.00cvss 6.5epss 0.00

    ruoyi-vue-pro through 2026.05, fixed in commit c779a47, contains a missing authorization vulnerability in the CRM module's GET /admin-api/crm/follow-up-record/get endpoint that allows authenticated users to read any follow-up record by iterating sequential numeric IDs. Attackers…