Ruoyi
by Ruoyi
Source repositories
CVEs (49)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-41599 | 0.00 | — | 0.00 | Jul 19, 2024 | Cross Site Scripting vulnerability in RuoYi v.4.7.9 and before allows a remote attacker to execute arbitrary code via the file upload method | |||
| CVE-2024-29400 | 0.00 | — | 0.01 | Apr 12, 2024 | An issue was discovered in RuoYi v4.5.1, allows attackers to obtain sensitive information via the status parameter. | |||
| CVE-2023-52048 | 0.00 | — | 0.00 | Feb 28, 2024 | RuoYi v4.7.8 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /system/notice/. | |||
| CVE-2023-27025 | 0.00 | — | 0.00 | Apr 2, 2023 | An arbitrary file download vulnerability in the background management module of RuoYi v4.7.6 and below allows attackers to download arbitrary files in the server. | |||
| CVE-2022-48114 | 0.00 | — | 0.01 | Feb 2, 2023 | RuoYi up to v4.7.5 was discovered to contain a SQL injection vulnerability via the component /tool/gen/createTable. | |||
| CVE-2022-37158 | 0.00 | — | 0.01 | Aug 25, 2022 | RuoYi v3.8.3 has a Weak password vulnerability in the management system. | |||
| CVE-2022-32065 | 0.00 | — | 0.01 | Jul 13, 2022 | An arbitrary file upload vulnerability in the background management module of RuoYi v4.7.3 and below allows attackers to execute arbitrary code via a crafted HTML file. | |||
| CVE-2022-23869 | 0.00 | — | 0.01 | Mar 30, 2022 | In RuoYi v4.7.2 through the WebUI, user test1 does not have permission to reset the password of user test3, but the password of user test3 can be reset through the /system/user/resetPwd request. | |||
| CVE-2022-23868 | 0.00 | — | 0.01 | Mar 30, 2022 | RuoYi v4.7.2 contains a CSV injection vulnerability through ruoyi-admin when a victim opens .xlsx log file. |
- CVE-2024-41599Jul 19, 2024risk 0.00cvss —epss 0.00
Cross Site Scripting vulnerability in RuoYi v.4.7.9 and before allows a remote attacker to execute arbitrary code via the file upload method
- CVE-2024-29400Apr 12, 2024risk 0.00cvss —epss 0.01
An issue was discovered in RuoYi v4.5.1, allows attackers to obtain sensitive information via the status parameter.
- CVE-2023-52048Feb 28, 2024risk 0.00cvss —epss 0.00
RuoYi v4.7.8 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /system/notice/.
- CVE-2023-27025Apr 2, 2023risk 0.00cvss —epss 0.00
An arbitrary file download vulnerability in the background management module of RuoYi v4.7.6 and below allows attackers to download arbitrary files in the server.
- CVE-2022-48114Feb 2, 2023risk 0.00cvss —epss 0.01
RuoYi up to v4.7.5 was discovered to contain a SQL injection vulnerability via the component /tool/gen/createTable.
- CVE-2022-37158Aug 25, 2022risk 0.00cvss —epss 0.01
RuoYi v3.8.3 has a Weak password vulnerability in the management system.
- CVE-2022-32065Jul 13, 2022risk 0.00cvss —epss 0.01
An arbitrary file upload vulnerability in the background management module of RuoYi v4.7.3 and below allows attackers to execute arbitrary code via a crafted HTML file.
- CVE-2022-23869Mar 30, 2022risk 0.00cvss —epss 0.01
In RuoYi v4.7.2 through the WebUI, user test1 does not have permission to reset the password of user test3, but the password of user test3 can be reset through the /system/user/resetPwd request.
- CVE-2022-23868Mar 30, 2022risk 0.00cvss —epss 0.01
RuoYi v4.7.2 contains a CSV injection vulnerability through ruoyi-admin when a victim opens .xlsx log file.
Page 3 of 3