CVE-2026-2947
- EPSS 0.03%
- Veröffentlicht 22.02.2026 13:32:46
- Zuletzt bearbeitet 25.02.2026 18:18:38
A vulnerability was detected in rymcu forest up to 0.0.5. This affects the function updateUserInfo of the file - src/main/java/com/rymcu/forest/web/api/user/UserInfoController.java of the component User Profile Handler. The manipulation results in cr...
CVE-2026-2946
- EPSS 0.03%
- Veröffentlicht 22.02.2026 13:16:13
- Zuletzt bearbeitet 25.02.2026 18:34:04
A security vulnerability has been detected in rymcu forest up to 0.0.5. Affected by this issue is the function XssUtils.replaceHtmlCode of the file src/main/java/com/rymcu/forest/util/XssUtils.java of the component Article Content/Comments/Portfolio....
CVE-2025-12925
- EPSS 0.06%
- Veröffentlicht 10.11.2025 01:32:06
- Zuletzt bearbeitet 24.02.2026 07:16:42
A security flaw has been discovered in rymcu forest up to de53ce79db9faa2efc4e79ce1077a302c42a1224. Impacted is the function getAll/addDic/getAllDic/deleteDic of the file src/main/java/com/rymcu/forest/lucene/api/UserDicController.java. The manipulat...
CVE-2025-12924
- EPSS 0.04%
- Veröffentlicht 10.11.2025 01:02:05
- Zuletzt bearbeitet 24.02.2026 07:16:41
A vulnerability was identified in rymcu forest up to de53ce79db9faa2efc4e79ce1077a302c42a1224. This issue affects the function GlobalResult of the file src/main/java/com/rymcu/forest/web/api/bank/BankController.java. The manipulation leads to missing...
CVE-2025-63687
- EPSS 0.05%
- Veröffentlicht 07.11.2025 00:00:00
- Zuletzt bearbeitet 21.01.2026 21:05:34
An issue was discovered in rymcu forest thru commit f782e85 (2025-09-04) in function doBefore in file src/main/java/com/rymcu/forest/core/service/security/AuthorshipAspect.java, allowing authorized attackers to delete arbitrary users posts.
CVE-2023-51804
- EPSS 0.16%
- Veröffentlicht 13.01.2024 02:15:07
- Zuletzt bearbeitet 03.06.2025 14:15:35
An issue in rymcu forest v.0.02 allows a remote attacker to obtain sensitive information via manipulation of the HTTP body URL in the com.rymcu.forest.web.api.common.UploadController file.