CVE-2025-70986
- EPSS 0.02%
- Veröffentlicht 23.01.2026 00:00:00
- Zuletzt bearbeitet 30.01.2026 21:26:10
Incorrect access control in the selectDept function of RuoYi v4.8.2 allows unauthorized attackers to arbitrarily access sensitive department data.
CVE-2025-70985
- EPSS 0.01%
- Veröffentlicht 23.01.2026 00:00:00
- Zuletzt bearbeitet 30.01.2026 21:27:40
Incorrect access control in the update function of RuoYi v4.8.2 allows unauthorized attackers to arbitrarily modify data outside of their scope.
- EPSS 0.41%
- Veröffentlicht 23.12.2025 00:00:00
- Zuletzt bearbeitet 06.01.2026 17:34:03
SQL Injection vulnerability in RuoYi v.4.7.9 and before allows a remote attacker to execute arbitrary code via the createTable function in SqlUtil.java.
CVE-2025-14856
- EPSS 0.06%
- Veröffentlicht 18.12.2025 01:32:07
- Zuletzt bearbeitet 24.02.2026 06:16:26
A security vulnerability has been detected in y_project RuoYi up to 4.8.1. The affected element is an unknown function of the file /monitor/cache/getnames. Such manipulation of the argument fragment leads to code injection. The attack can be executed...
CVE-2025-67342
- EPSS 0.03%
- Veröffentlicht 12.12.2025 00:00:00
- Zuletzt bearbeitet 19.12.2025 15:44:54
RuoYi versions 4.8.1 and earlier is affected by a stored XSS vulnerability in the /system/menu/edit endpoint. While the endpoint is protected by an XSS filter, the protection can be bypassed. Additionally, because the menu is shared across all users,...
CVE-2025-46175
- EPSS 0.04%
- Veröffentlicht 26.11.2025 00:00:00
- Zuletzt bearbeitet 04.12.2025 17:15:54
Ruoyi v4.8.0 is vulnerable to Incorrect Access Control. There is a missing checkUserDataScope permission check in the authRole method of SysUserController.java.
CVE-2025-56396
- EPSS 0.06%
- Veröffentlicht 26.11.2025 00:00:00
- Zuletzt bearbeitet 04.12.2025 20:16:19
An issue was discovered in Ruoyi 4.8.1 allowing attackers to gain escalated privileges due to the owning department having higher rights than the active user.
CVE-2025-46174
- EPSS 0.04%
- Veröffentlicht 26.11.2025 00:00:00
- Zuletzt bearbeitet 04.12.2025 19:16:03
Ruoyi v4.8.0 vulnerable to Incorrect Access Control. There is a missing checkUserDataScope permission check in the resetPwd Method of SysUserController.java.
CVE-2025-10989
- EPSS 0.03%
- Veröffentlicht 26.09.2025 01:15:36
- Zuletzt bearbeitet 03.10.2025 20:23:41
A security flaw has been discovered in yangzongzhuan RuoYi up to 4.8.1. This vulnerability affects unknown code of the file /system/role/authUser/selectAll. Performing manipulation of the argument userIds results in improper authorization. The attack...
CVE-2025-10473
- EPSS 0.03%
- Veröffentlicht 15.09.2025 19:15:34
- Zuletzt bearbeitet 17.09.2025 17:00:22
A security flaw has been discovered in yangzongzhuan RuoYi up to 4.8.1. This impacts the function filterKeyword of the file /com/ruoyi/common/utils/sql/SqlUtil.java of the component Blacklist Handler. The manipulation results in sql injection. The at...