VYPR
Vendor

Dromara

Products
14
CVEs
40
Across products
41
Status
Private

Products

14

Recent CVEs

40
View all 40 CVEs →
  • CVE-2024-45944CriOct 18, 2024
    risk 0.64cvss 9.8epss 0.01

    In J2eeFAST <=2.7, the backend function has unsafe filtering, which allows an attacker to trigger certain sensitive functions resulting in arbitrary code execution.

  • CVE-2025-66916CriJan 8, 2026
    risk 0.61cvss 9.4epss 0.01

    The snailjob component in RuoYi-Vue-Plus versions 5.5.1 and earlier, interface /snail-job/workflow/check-node-expression can execute QLExpress expressions, but it does not filter user input, allowing attackers to use the File class to perform arbitrary file reading and writing.

  • CVE-2026-69102CriAug 11, 2026
    risk 0.57cvss 9.8epss 0.00

    MaxKey contains an unauthorized access vulnerability due to a hard-coded JWT signing secret in application-maxkey.properties that allows unauthenticated attackers to forge valid JWT tokens and authenticate as any user by exploiting the password-skipped login endpoint. Attackers…

  • CVE-2023-31579CriNov 2, 2023
    risk 0.57cvss 9.8epss 0.01

    Dromara Lamp-Cloud before v3.8.1 was discovered to use a hardcoded cryptographic key when creating and verifying a Json Web Token. This vulnerability allows attackers to authenticate to the application via a crafted JWT token.

  • CVE-2023-44794CriOct 25, 2023
    risk 0.57cvss 9.8epss 0.01

    An issue in Dromara SaToken version 1.36.0 and before allows a remote attacker to escalate privileges via a crafted payload to the URL.

  • CVE-2023-43961HigOct 25, 2023
    risk 0.57cvss 8.8epss 0.01

    An issue in Dromara SaToken version 1.3.50RC and before when using Spring dynamic controllers, a specially crafted request may cause an authentication bypass.

  • CVE-2023-31581CriOct 25, 2023
    risk 0.57cvss 9.8epss 0.01

    Dromara Sureness before v1.0.8 was discovered to use a hardcoded key.

  • CVE-2026-69100HigAug 4, 2026
    risk 0.50cvss 8.8epss 0.01

    LAMP Rapid Development Platform through 5.6.2, fixed in commit 84b0c27, contains a remote code execution vulnerability in GlueFactory that executes unsandboxed Groovy scripts from database template fields without compilation restrictions or whitelisting. Attackers can write or…

  • CVE-2024-42361HigAug 20, 2024
    risk 0.49cvss 7.5epss 0.01

    Hertzbeat is an open source, real-time monitoring system. Hertzbeat 1.6.0 and earlier declares a /api/monitor/{monitorId}/metric/{metricFull} endpoint to download job metrics. In the process, it executes a SQL query with user-controlled data, allowing for SQL injection.

  • CVE-2023-51650HigDec 22, 2023
    risk 0.49cvss 7.5epss 0.01

    Hertzbeat is an open source, real-time monitoring system. Prior to version 1.4.1, Spring Boot permission configuration issues caused unauthorized access vulnerabilities to three interfaces. This could result in disclosure of sensitive server information. Version 1.4.1 fixes this…

  • CVE-2026-19758HigAug 14, 2026
    risk 0.47cvss 7.3epss

    A vulnerability was determined in dromara lamp-cloud up to 5.10.0. This issue affects some unknown processing of the file FileChunkController.java of the component chunk-check endpoint. Executing a manipulation of the argument Name can lead to path traversal. The attack can be…

  • CVE-2026-19757HigAug 14, 2026
    risk 0.47cvss 7.3epss

    A vulnerability was found in Dromara lamp-cloud up to 5.10.0. This vulnerability affects unknown code of the file FileAnyoneController.java of the component File-Upload Controller. Performing a manipulation of the argument bucket/bizType results in path traversal. The attack can…

  • CVE-2026-67345HigJul 30, 2026
    risk 0.46cvss 8.1epss 0.00

    MaxKey through 4.1.12, fixed in commit ddbb72f, contains an insufficient redirect URI validation vulnerability in DefaultRedirectResolver.hostMatches() that allows remote attackers to hijack OAuth 2.0 authorization codes by supplying a crafted redirect_uri whose hostname suffix…

  • CVE-2026-19756MedAug 13, 2026
    risk 0.41cvss 6.3epss

    A vulnerability has been found in Dromara lamp-cloud up to 5.10.0. This affects an unknown part of the file DefGenProjectController.java of the component Code Generator. Such manipulation of the argument outputDir/parent/projectPrefix leads to path traversal. It is possible to…

  • CVE-2026-9498MedMay 25, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability has been found in Dromara lamp-cloud up to 5.6.2. Impacted is the function GroovyClassLoader.parseClass of the component Message Template Handler. Such manipulation of the argument DefMsgTemplate.content leads to improper neutralization of special elements used…

  • CVE-2026-7699MedMay 3, 2026
    risk 0.41cvss 6.3epss 0.00

    A security flaw has been discovered in Dromara MaxKey up to 3.5.13. Affected by this issue is the function StrUtils.checkSqlInjection of the file StrUtils.java. Performing a manipulation of the argument filtersfields results in sql injection. The attack is possible to be carried…

  • CVE-2026-2954MedFeb 22, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was found in Dromara UJCMS 10.0.2. Impacted is the function importChanel of the file /api/backend/ext/import-data/import-channel of the component ImportDataController. Performing a manipulation of the argument driverClassName/url results in injection. It is…

  • CVE-2026-2819MedFeb 20, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was identified in Dromara RuoYi-Vue-Plus up to 5.5.3. This vulnerability affects the function SaServletFilter of the file /workflow/instance/deleteByInstanceIds of the component Workflow Module. The manipulation leads to missing authorization. The attack may be…

  • CVE-2025-13268MedNov 17, 2025
    risk 0.41cvss 6.3epss 0.00

    A flaw has been found in Dromara dataCompare up to 1.0.1. The affected element is the function DbConfig of the file src/main/java/com/vince/xq/project/system/dbconfig/service/DbconfigServiceImpl.java of the component JDBC URL Handler. Executing manipulation can lead to…

  • CVE-2025-7552MedJul 14, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was found in Dromara Northstar up to 7.3.5. It has been rated as critical. Affected by this issue is the function preHandle of the file northstar-main/src/main/java/org/dromara/northstar/web/interceptor/AuthorizationInterceptor.java of the component Path Handler.…