Rymcu

Forest

6 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.03%
  • Veröffentlicht 22.02.2026 13:32:46
  • Zuletzt bearbeitet 25.02.2026 18:18:38

A vulnerability was detected in rymcu forest up to 0.0.5. This affects the function updateUserInfo of the file - src/main/java/com/rymcu/forest/web/api/user/UserInfoController.java of the component User Profile Handler. The manipulation results in cr...

Exploit
  • EPSS 0.03%
  • Veröffentlicht 22.02.2026 13:16:13
  • Zuletzt bearbeitet 25.02.2026 18:34:04

A security vulnerability has been detected in rymcu forest up to 0.0.5. Affected by this issue is the function XssUtils.replaceHtmlCode of the file src/main/java/com/rymcu/forest/util/XssUtils.java of the component Article Content/Comments/Portfolio....

Exploit
  • EPSS 0.06%
  • Veröffentlicht 10.11.2025 01:32:06
  • Zuletzt bearbeitet 24.02.2026 07:16:42

A security flaw has been discovered in rymcu forest up to de53ce79db9faa2efc4e79ce1077a302c42a1224. Impacted is the function getAll/addDic/getAllDic/deleteDic of the file src/main/java/com/rymcu/forest/lucene/api/UserDicController.java. The manipulat...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 10.11.2025 01:02:05
  • Zuletzt bearbeitet 24.02.2026 07:16:41

A vulnerability was identified in rymcu forest up to de53ce79db9faa2efc4e79ce1077a302c42a1224. This issue affects the function GlobalResult of the file src/main/java/com/rymcu/forest/web/api/bank/BankController.java. The manipulation leads to missing...

Exploit
  • EPSS 0.05%
  • Veröffentlicht 07.11.2025 00:00:00
  • Zuletzt bearbeitet 21.01.2026 21:05:34

An issue was discovered in rymcu forest thru commit f782e85 (2025-09-04) in function doBefore in file src/main/java/com/rymcu/forest/core/service/security/AuthorshipAspect.java, allowing authorized attackers to delete arbitrary users posts.

Exploit
  • EPSS 0.16%
  • Veröffentlicht 13.01.2024 02:15:07
  • Zuletzt bearbeitet 03.06.2025 14:15:35

An issue in rymcu forest v.0.02 allows a remote attacker to obtain sensitive information via manipulation of the HTTP body URL in the com.rymcu.forest.web.api.common.UploadController file.