VYPR

Ruoyi

by Ruoyi

Source repositories

CVEs (49)

  • CVE-2024-41599Jul 19, 2024
    risk 0.00cvss epss 0.00

    Cross Site Scripting vulnerability in RuoYi v.4.7.9 and before allows a remote attacker to execute arbitrary code via the file upload method

  • CVE-2024-29400Apr 12, 2024
    risk 0.00cvss epss 0.01

    An issue was discovered in RuoYi v4.5.1, allows attackers to obtain sensitive information via the status parameter.

  • CVE-2023-52048Feb 28, 2024
    risk 0.00cvss epss 0.00

    RuoYi v4.7.8 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /system/notice/.

  • CVE-2023-27025Apr 2, 2023
    risk 0.00cvss epss 0.00

    An arbitrary file download vulnerability in the background management module of RuoYi v4.7.6 and below allows attackers to download arbitrary files in the server.

  • CVE-2022-48114Feb 2, 2023
    risk 0.00cvss epss 0.01

    RuoYi up to v4.7.5 was discovered to contain a SQL injection vulnerability via the component /tool/gen/createTable.

  • CVE-2022-37158Aug 25, 2022
    risk 0.00cvss epss 0.01

    RuoYi v3.8.3 has a Weak password vulnerability in the management system.

  • CVE-2022-32065Jul 13, 2022
    risk 0.00cvss epss 0.01

    An arbitrary file upload vulnerability in the background management module of RuoYi v4.7.3 and below allows attackers to execute arbitrary code via a crafted HTML file.

  • CVE-2022-23869Mar 30, 2022
    risk 0.00cvss epss 0.01

    In RuoYi v4.7.2 through the WebUI, user test1 does not have permission to reset the password of user test3, but the password of user test3 can be reset through the /system/user/resetPwd request.

  • CVE-2022-23868Mar 30, 2022
    risk 0.00cvss epss 0.01

    RuoYi v4.7.2 contains a CSV injection vulnerability through ruoyi-admin when a victim opens .xlsx log file.

Page 3 of 3