« Volver al listado

Iocoder

Iocoder Ruoyi-vue-pro: vulnerabilidades y CVE

Iocoder Ruoyi-vue-pro tiene 16 vulnerabilidades publicadas, 6 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE16
Últimos 12 meses6
Críticas1
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-97325Baja (2.1)0.26%—24 sept 2026
A security flaw has been discovered in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. Affected by this vulnerability is the function validOAuthClientFromCache of the file…
CVE-2026-97324Media (5.5)0.28%—24 sept 2026
A vulnerability was identified in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. Affected is the function updateDemoOrderPaid of the file…
CVE-2026-97322Baja (2.1)0.26%—24 sept 2026
A vulnerability was found in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. This affects an unknown function of the file…
CVE-2026-97321Baja (2.1)0.23%—24 sept 2026
A vulnerability has been found in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. The impacted element is the function GoViewDataServiceImpl.getDataBySQL of the file…
CVE-2026-97320Baja (2.1)0.20%—24 sept 2026
A flaw has been found in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. The affected element is the function AiKnowledgeDocumentServiceImpl.readUrl of the file AiKnowledgeDocumentServiceImpl.java of the component AI…
CVE-2026-13528Media (5.5)0.65%—29 jun 2026
A vulnerability was found in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.04-jdk8-SNAPSHOT. The impacted element is the function generateUploadPath of the file…
CVE-2025-10988Baja (2.1)0.32%—26 sept 2025
A vulnerability was identified in YunaiV ruoyi-vue-pro up to 2025.09. This affects an unknown part of the file /crm/business/transfer. Such manipulation leads to improper authorization. It is possible to launch the…
CVE-2025-10278Baja (2.1)0.33%—12 sept 2025
A flaw has been found in YunaiV ruoyi-vue-pro up to 2025.09. Impacted is an unknown function of the file /crm/contact/transfer. This manipulation of the argument ids/newOwnerUserId causes improper authorization. The…
CVE-2025-10276Baja (2.1)0.33%—12 sept 2025
A security vulnerability has been detected in YunaiV ruoyi-vue-pro up to 2025.09. This vulnerability affects unknown code of the file /crm/contract/transfer. The manipulation of the argument id/newOwnerUserId leads to…
CVE-2025-2744Media (5.3)0.73%—25 mar 2025
A vulnerability, which was classified as critical, was found in zhijiantianya ruoyi-vue-pro 2.4.1. Affected is an unknown function of the file /admin-api/mp/material/upload-news-image of the component Material Upload…
CVE-2025-2743Media (5.3)0.87%—25 mar 2025
A vulnerability, which was classified as problematic, has been found in zhijiantianya ruoyi-vue-pro 2.4.1. This issue affects some unknown processing of the file /admin-api/mp/material/upload-temporary of the component…
CVE-2025-2742Media (5.3)0.87%—25 mar 2025
A vulnerability classified as critical was found in zhijiantianya ruoyi-vue-pro 2.4.1. This vulnerability affects unknown code of the file /admin-api/mp/material/upload-permanent of the component Material Upload…
CVE-2025-2708Media (5.3)0.92%—24 mar 2025
A vulnerability, which was classified as critical, was found in zhijiantianya ruoyi-vue-pro 2.4.1. This affects an unknown part of the file /admin-api/infra/file/upload of the component Backend File Upload Interface.…
CVE-2025-2707Media (5.3)0.92%—24 mar 2025
A vulnerability, which was classified as critical, has been found in zhijiantianya ruoyi-vue-pro 2.4.1. Affected by this issue is some unknown functionality of the file /app-api/infra/file/upload of the component…
CVE-2025-2040Media (5.3)0.49%—6 mar 2025
A vulnerability classified as critical was found in zhijiantianya ruoyi-vue-pro 2.4.1. Affected by this vulnerability is an unknown functionality of the file /admin-api/bpm/model/deploy. The manipulation leads to…
CVE-2022-37158Crítica (9.8)0.95%—25 ago 2022
RuoYi v3.8.3 has a Weak password vulnerability in the management system.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1189 Drive-by Compromise2
  2. T1210 Exploitation of Remote Services2
  3. T1005 Data from Local System1
  4. T1059.007 JavaScript1
  5. T1078.001 Default Accounts1
  6. T1090 Proxy1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Iocoder