Iocoder
Iocoder Yudao-cloud: vulnerabilidades y CVE
Iocoder Yudao-cloud tiene 10 vulnerabilidades publicadas, 7 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE10
Últimos 12 meses7
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-58448 | Alta (7.1) | 0.40% | — | 30 jun 2026 | yudao-cloud before 2026.06 contains a broken access control vulnerability in the BPM module that allows any authenticated user to access arbitrary process instance records by supplying a caller-controlled… |
| CVE-2026-9464 | Baja (2) | 0.38% | — | 25 may 2026 | A vulnerability has been found in YunaiV yudao-cloud 2026.03. This affects the function IotDataSinkHttpConfig of the file /admin-api/iot/data-sink/create of the component Admin API Endpoint. Such manipulation leads to… |
| CVE-2026-7710 | Media (5.5) | 0.65% | — | 4 may 2026 | A security flaw has been discovered in YunaiV yudao-cloud up to 3.8.0. This affects the function doFilterInternal of the file JwtAuthenticationTokenFilter.java of the component Ruoyi-Vue-Pro. Performing a manipulation… |
| CVE-2026-7678 | Baja (2.1) | 0.32% | — | 3 may 2026 | A vulnerability was identified in YunaiV yudao-cloud up to 2026.01. This affects the function getDataBySQL of the file… |
| CVE-2026-5148 | Baja (2) | 0.33% | — | 30 mar 2026 | A weakness has been identified in YunaiV yudao-cloud up to 2026.01. This vulnerability affects unknown code of the file /admin-api/system/mail-log/page. This manipulation of the argument toMail causes sql injection. The… |
| CVE-2026-5147 | Media (5.5) | 0.41% | — | 30 mar 2026 | A security flaw has been discovered in YunaiV yudao-cloud up to 2026.01. This affects an unknown part of the file /admin-api/system/tenant/get-by-website. The manipulation of the argument Website results in sql… |
| CVE-2025-15098 | Baja (2.1) | 0.29% | — | 26 dic 2025 | A vulnerability was determined in YunaiV yudao-cloud up to 2025.11. This affects the function BpmHttpCallbackTrigger/BpmSyncHttpRequestTrigger of the component Business Process Management. Executing manipulation of the… |
| CVE-2025-10987 | Baja (2.1) | 0.32% | — | 26 sept 2025 | A vulnerability was determined in YunaiV yudao-cloud up to 2025.09. Affected by this issue is some unknown functionality of the file /crm/contact/transfer of the component HTTP Request Handler. This manipulation of the… |
| CVE-2025-10277 | Baja (2.1) | 0.32% | — | 12 sept 2025 | A vulnerability was detected in YunaiV yudao-cloud up to 2025.09. This issue affects some unknown processing of the file /crm/receivable/submit. The manipulation of the argument ID results in improper authorization. The… |
| CVE-2025-10275 | Baja (2.1) | 0.32% | — | 12 sept 2025 | A weakness has been identified in YunaiV yudao-cloud up to 2025.09. This affects an unknown part of the file /crm/business/transfer. Executing manipulation of the argument ids/newOwnerUserId can lead to improper… |