Ruoyi
Products
3- 60 CVEs
- 1 CVE
- 1 CVE
Recent CVEs
62| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-57521 | Cri | 0.65 | 10.0 | 0.01 | Dec 23, 2025 | SQL Injection vulnerability in RuoYi v.4.7.9 and before allows a remote attacker to execute arbitrary code via the createTable function in SqlUtil.java. | ||
| CVE-2026-38812 | Cri | 0.64 | 9.8 | 0.00 | Jun 15, 2026 | RuoYi v4.8.2 is vulnerable to SQL Injection via the /tool/gen/createTable endpoint. The issue affects the code generation module and may allow an authenticated attacker with administrative privileges to access sensitive database information. | ||
| CVE-2025-28413 | Cri | 0.64 | 9.8 | 0.01 | Apr 7, 2025 | An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the SysDictTypeController component | ||
| CVE-2025-28412 | Cri | 0.64 | 9.8 | 0.01 | Apr 7, 2025 | An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the /editSave method in SysNoticeController | ||
| CVE-2025-28411 | Cri | 0.64 | 9.8 | 0.01 | Apr 7, 2025 | An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the editSave method in /tool/gen/editSave | ||
| CVE-2025-28410 | Cri | 0.64 | 9.8 | 0.01 | Apr 7, 2025 | An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the cancelAuthUserAll method does not properly validate whether the requesting user has administrative privileges | ||
| CVE-2025-28408 | Cri | 0.64 | 9.8 | 0.01 | Apr 7, 2025 | An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the selectDeptTree method of the /selectDeptTree/{deptId} endpoint does not properly validate the deptId parameter | ||
| CVE-2025-28406 | Cri | 0.64 | 9.8 | 0.01 | Apr 7, 2025 | An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the jobLogId parameter | ||
| CVE-2025-28405 | Cri | 0.64 | 9.8 | 0.01 | Apr 7, 2025 | An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the changeStatus method | ||
| CVE-2025-28402 | Cri | 0.64 | 9.8 | 0.01 | Apr 7, 2025 | An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the jobId parameter | ||
| CVE-2024-46076 | Cri | 0.64 | 9.8 | 0.01 | Oct 7, 2024 | RuoYi v4.7.9 and before has a security flaw that allows escaping from comments within the code generation feature, enabling the injection of malicious code. | ||
| CVE-2024-42913 | Cri | 0.64 | 9.8 | 0.00 | Aug 26, 2024 | RuoYi CMS v4.7.9 was discovered to contain a SQL injection vulnerability via the job_id parameter at /sasfs1. | ||
| CVE-2023-49371 | Cri | 0.64 | 9.8 | 0.04 | Dec 1, 2023 | RuoYi up to v4.6 was discovered to contain a SQL injection vulnerability via /system/dept/edit. | ||
| CVE-2021-28411 | Cri | 0.64 | 9.8 | 0.01 | Aug 11, 2023 | An issue was discovered in getRememberedSerializedIdentity function in CookieRememberMeManager class in lerry903 RuoYi version 3.4.0, allows remote attackers to escalate privileges. | ||
| CVE-2022-48114 | Cri | 0.64 | 9.8 | 0.01 | Feb 2, 2023 | RuoYi up to v4.7.5 was discovered to contain a SQL injection vulnerability via the component /tool/gen/createTable. | ||
| CVE-2021-38241 | Cri | 0.64 | 9.8 | 0.01 | Dec 16, 2022 | Deserialization issue discovered in Ruoyi before 4.6.1 allows remote attackers to run arbitrary code via weak cipher in Shiro framework. | ||
| CVE-2022-37158 | Cri | 0.64 | 9.8 | 0.01 | Aug 25, 2022 | RuoYi v3.8.3 has a Weak password vulnerability in the management system. | ||
| CVE-2025-70985 | Cri | 0.59 | 9.1 | 0.00 | Jan 23, 2026 | Incorrect access control in the update function of RuoYi v4.8.2 allows unauthorized attackers to arbitrarily modify data outside of their scope. | ||
| CVE-2025-56396 | Hig | 0.57 | 8.8 | 0.00 | Nov 26, 2025 | An issue was discovered in Ruoyi 4.8.1 allowing attackers to gain escalated privileges due to the owning department having higher rights than the active user. | ||
| CVE-2025-28409 | Hig | 0.57 | 8.8 | 0.01 | Apr 7, 2025 | An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the add method of the /add/{parentId} endpoint does not properly validate whether the requesting user has permission to add a menu item under the specified parentId |
- risk 0.65cvss 10.0epss 0.01
SQL Injection vulnerability in RuoYi v.4.7.9 and before allows a remote attacker to execute arbitrary code via the createTable function in SqlUtil.java.
- risk 0.64cvss 9.8epss 0.00
RuoYi v4.8.2 is vulnerable to SQL Injection via the /tool/gen/createTable endpoint. The issue affects the code generation module and may allow an authenticated attacker with administrative privileges to access sensitive database information.
- risk 0.64cvss 9.8epss 0.01
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the SysDictTypeController component
- risk 0.64cvss 9.8epss 0.01
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the /editSave method in SysNoticeController
- risk 0.64cvss 9.8epss 0.01
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the editSave method in /tool/gen/editSave
- risk 0.64cvss 9.8epss 0.01
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the cancelAuthUserAll method does not properly validate whether the requesting user has administrative privileges
- risk 0.64cvss 9.8epss 0.01
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the selectDeptTree method of the /selectDeptTree/{deptId} endpoint does not properly validate the deptId parameter
- risk 0.64cvss 9.8epss 0.01
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the jobLogId parameter
- risk 0.64cvss 9.8epss 0.01
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the changeStatus method
- risk 0.64cvss 9.8epss 0.01
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the jobId parameter
- risk 0.64cvss 9.8epss 0.01
RuoYi v4.7.9 and before has a security flaw that allows escaping from comments within the code generation feature, enabling the injection of malicious code.
- risk 0.64cvss 9.8epss 0.00
RuoYi CMS v4.7.9 was discovered to contain a SQL injection vulnerability via the job_id parameter at /sasfs1.
- risk 0.64cvss 9.8epss 0.04
RuoYi up to v4.6 was discovered to contain a SQL injection vulnerability via /system/dept/edit.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in getRememberedSerializedIdentity function in CookieRememberMeManager class in lerry903 RuoYi version 3.4.0, allows remote attackers to escalate privileges.
- risk 0.64cvss 9.8epss 0.01
RuoYi up to v4.7.5 was discovered to contain a SQL injection vulnerability via the component /tool/gen/createTable.
- risk 0.64cvss 9.8epss 0.01
Deserialization issue discovered in Ruoyi before 4.6.1 allows remote attackers to run arbitrary code via weak cipher in Shiro framework.
- risk 0.64cvss 9.8epss 0.01
RuoYi v3.8.3 has a Weak password vulnerability in the management system.
- risk 0.59cvss 9.1epss 0.00
Incorrect access control in the update function of RuoYi v4.8.2 allows unauthorized attackers to arbitrarily modify data outside of their scope.
- risk 0.57cvss 8.8epss 0.00
An issue was discovered in Ruoyi 4.8.1 allowing attackers to gain escalated privileges due to the owning department having higher rights than the active user.
- risk 0.57cvss 8.8epss 0.01
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the add method of the /add/{parentId} endpoint does not properly validate whether the requesting user has permission to add a menu item under the specified parentId