CVE-2026-38812
- EPSS 0.39%
- Veröffentlicht 15.06.2026 00:00:00
- Zuletzt bearbeitet 16.06.2026 15:50:58
RuoYi v4.8.2 is vulnerable to SQL Injection via the /tool/gen/createTable endpoint. The issue affects the code generation module and may allow an authenticated attacker with administrative privileges to access sensitive database information.
CVE-2026-37216
- EPSS 0.18%
- Veröffentlicht 15.06.2026 00:00:00
- Zuletzt bearbeitet 16.06.2026 19:16:35
Ruoyi 4.8.2 is vulnerable to Cross Site Scripting (XSS) at the interface /system/notice/add.
CVE-2025-70986
- EPSS 0.4%
- Veröffentlicht 23.01.2026 00:00:00
- Zuletzt bearbeitet 30.01.2026 21:26:10
Incorrect access control in the selectDept function of RuoYi v4.8.2 allows unauthorized attackers to arbitrarily access sensitive department data.
CVE-2025-70985
- EPSS 0.38%
- Veröffentlicht 23.01.2026 00:00:00
- Zuletzt bearbeitet 30.01.2026 21:27:40
Incorrect access control in the update function of RuoYi v4.8.2 allows unauthorized attackers to arbitrarily modify data outside of their scope.
- EPSS 0.59%
- Veröffentlicht 23.12.2025 00:00:00
- Zuletzt bearbeitet 06.01.2026 17:34:03
SQL Injection vulnerability in RuoYi v.4.7.9 and before allows a remote attacker to execute arbitrary code via the createTable function in SqlUtil.java.
CVE-2025-14856
- EPSS 0.38%
- Veröffentlicht 18.12.2025 01:32:07
- Zuletzt bearbeitet 29.04.2026 01:00:01
A security vulnerability has been detected in y_project RuoYi up to 4.8.1. The affected element is an unknown function of the file /monitor/cache/getnames. Such manipulation of the argument fragment leads to code injection. The attack can be executed...
CVE-2025-67342
- EPSS 0.15%
- Veröffentlicht 12.12.2025 00:00:00
- Zuletzt bearbeitet 19.12.2025 15:44:54
RuoYi versions 4.8.1 and earlier is affected by a stored XSS vulnerability in the /system/menu/edit endpoint. While the endpoint is protected by an XSS filter, the protection can be bypassed. Additionally, because the menu is shared across all users,...
CVE-2025-46175
- EPSS 0.27%
- Veröffentlicht 26.11.2025 00:00:00
- Zuletzt bearbeitet 04.12.2025 17:15:54
Ruoyi v4.8.0 is vulnerable to Incorrect Access Control. There is a missing checkUserDataScope permission check in the authRole method of SysUserController.java.
CVE-2025-56396
- EPSS 0.28%
- Veröffentlicht 26.11.2025 00:00:00
- Zuletzt bearbeitet 04.12.2025 20:16:19
An issue was discovered in Ruoyi 4.8.1 allowing attackers to gain escalated privileges due to the owning department having higher rights than the active user.
CVE-2025-46174
- EPSS 0.27%
- Veröffentlicht 26.11.2025 00:00:00
- Zuletzt bearbeitet 04.12.2025 19:16:03
Ruoyi v4.8.0 vulnerable to Incorrect Access Control. There is a missing checkUserDataScope permission check in the resetPwd Method of SysUserController.java.