VYPR
Vendor

Dromara

Products
17
CVEs
57
Across products
58
Status
Private

Products

17

Recent CVEs

57
View all 57 CVEs →
  • CVE-2024-45944CriOct 18, 2024
    risk 0.64cvss 9.8epss 0.01

    In J2eeFAST <=2.7, the backend function has unsafe filtering, which allows an attacker to trigger certain sensitive functions resulting in arbitrary code execution.

  • CVE-2023-24162CriJan 31, 2023
    risk 0.64cvss 9.8epss 0.01

    Deserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parameter.

  • CVE-2025-66916CriJan 8, 2026
    risk 0.61cvss 9.4epss 0.01

    The snailjob component in RuoYi-Vue-Plus versions 5.5.1 and earlier, interface /snail-job/workflow/check-node-expression can execute QLExpress expressions, but it does not filter user input, allowing attackers to use the File class to perform arbitrary file reading and writing.

  • CVE-2026-88616HigSep 15, 2026
    risk 0.57cvss 8.8epss 0.01

    An issue in RuoYi-Vue-Plus 6.0.0 allows a remote attacker to execute arbitrary code via the FlwTaskController.java component, and the FlwTaskServiceImpl.completeTask, CompleteExecuteComponent.process, Warm-Flow TaskService.skip, POST /workflow/task/completeTask components

  • CVE-2026-69102CriAug 11, 2026
    risk 0.57cvss 9.8epss 0.01

    MaxKey contains an unauthorized access vulnerability due to a hard-coded JWT signing secret in application-maxkey.properties that allows unauthenticated attackers to forge valid JWT tokens and authenticate as any user by exploiting the password-skipped login endpoint. Attackers…

  • CVE-2023-31579CriNov 2, 2023
    risk 0.57cvss 9.8epss 0.01

    Dromara Lamp-Cloud before v3.8.1 was discovered to use a hardcoded cryptographic key when creating and verifying a Json Web Token. This vulnerability allows attackers to authenticate to the application via a crafted JWT token.

  • CVE-2023-44794CriOct 25, 2023
    risk 0.57cvss 9.8epss 0.01

    An issue in Dromara SaToken version 1.36.0 and before allows a remote attacker to escalate privileges via a crafted payload to the URL.

  • CVE-2023-43961HigOct 25, 2023
    risk 0.57cvss 8.8epss 0.01

    An issue in Dromara SaToken version 1.3.50RC and before when using Spring dynamic controllers, a specially crafted request may cause an authentication bypass.

  • CVE-2023-31581CriOct 25, 2023
    risk 0.57cvss 9.8epss 0.01

    Dromara Sureness before v1.0.8 was discovered to use a hardcoded key.

  • CVE-2023-24163CriJan 31, 2023
    risk 0.57cvss 9.8epss 0.01

    SQL Inection vulnerability in Dromara hutool before 5.8.21 allows attacker to execute arbitrary code via the aviator template engine.

  • CVE-2026-90510HigSep 13, 2026
    risk 0.54cvss 8.3epss 0.01

    A security vulnerability has been detected in dromara orion-visor up to 2.5.7. This affects the function HostKeyServiceImpl.encryptKey of the file orion-visor-modules/orion-visor-module-asset/orion-visor-module-asset-service/src/main/java/org/dromara/visor/module/asset/service/im…

  • CVE-2026-69100HigAug 4, 2026
    risk 0.50cvss 8.8epss 0.01

    LAMP Rapid Development Platform through 5.6.2, fixed in commit 84b0c27, contains a remote code execution vulnerability in GlueFactory that executes unsandboxed Groovy scripts from database template fields without compilation restrictions or whitelisting. Attackers can write or…

  • CVE-2026-91996HigSep 15, 2026
    risk 0.49cvss 7.5epss 0.01

    lamp-cloud through 5.10.0 whitelists the path pattern /*/anno/** for anonymous access, allowing unauthenticated attackers to read the server's full JVM system property map. Attackers can send POST requests to /defGenProject/anno/getProperties to retrieve sensitive information…

  • CVE-2024-42361HigAug 20, 2024
    risk 0.49cvss 7.5epss 0.01

    Hertzbeat is an open source, real-time monitoring system. Hertzbeat 1.6.0 and earlier declares a /api/monitor/{monitorId}/metric/{metricFull} endpoint to download job metrics. In the process, it executes a SQL query with user-controlled data, allowing for SQL injection.

  • CVE-2023-51650HigDec 22, 2023
    risk 0.49cvss 7.5epss 0.01

    Hertzbeat is an open source, real-time monitoring system. Prior to version 1.4.1, Spring Boot permission configuration issues caused unauthorized access vulnerabilities to three interfaces. This could result in disclosure of sensitive server information. Version 1.4.1 fixes this…

  • CVE-2026-90509HigSep 13, 2026
    risk 0.47cvss 7.3epss 0.01

    A weakness has been identified in dromara orion-visor up to 2.5.7. Affected by this issue is the function ExposeApiAspect.beforeExposeApi of the file ExposeApiAspect.java. Executing a manipulation can lead to hard-coded credentials. The attack can be executed remotely. The…

  • CVE-2026-19758HigAug 14, 2026
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was determined in dromara lamp-cloud up to 5.10.0. This issue affects some unknown processing of the file FileChunkController.java of the component chunk-check endpoint. Executing a manipulation of the argument Name can lead to path traversal. The attack can be…

  • CVE-2026-19757HigAug 14, 2026
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in Dromara lamp-cloud up to 5.10.0. This vulnerability affects unknown code of the file FileAnyoneController.java of the component File-Upload Controller. Performing a manipulation of the argument bucket/bizType results in path traversal. The attack can…

  • CVE-2026-94535HigSep 21, 2026
    risk 0.46cvss 7.1epss 0.00

    lamp-cloud through 5.10.0 contains an authorization bypass vulnerability in the deleteMyNotice endpoint that allows authenticated users to delete other users' notifications. Attackers can call the DELETE /anyone/extendNotice/deleteMyNotice endpoint with arbitrary notice IDs to…

  • CVE-2026-94534HigSep 21, 2026
    risk 0.46cvss 7.1epss 0.00

    lamp-cloud through 5.10.0 fails to validate user identity in PUT /anyone/baseInfo and PUT /anyone/avatar endpoints, allowing authenticated attackers to modify arbitrary user profiles. Attackers can supply target user IDs in request bodies to rewrite profile fields including…