📦 Ruoyi

by Ruoyi

🔍 What is Ruoyi?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-70985

CRITICAL CVSS 9.1 Jan 23, 2026

This vulnerability in RuoYi v4.8.2 allows unauthorized attackers to modify data they shouldn't have access to due to improper access control in the update function. Any organization using the vulnerab...

CVE-2025-28410

CRITICAL CVSS 9.8 Apr 7, 2025

A privilege escalation vulnerability in RUoYi v.4.8.0 allows remote attackers to gain administrative privileges. The cancelAuthUserAll method fails to properly validate whether the requesting user has...

CVE-2025-28412

CRITICAL CVSS 9.8 Apr 7, 2025

A privilege escalation vulnerability in RUoYi v.4.8.0 allows remote attackers to gain elevated privileges through the /editSave method in SysNoticeController. This affects all systems running the vuln...

CVE-2025-28402

CRITICAL CVSS 9.8 Apr 7, 2025

A privilege escalation vulnerability in RUoYi v.4.8.0 allows remote attackers to gain elevated privileges by manipulating the jobId parameter. This affects all systems running the vulnerable version o...

CVE-2025-28405

CRITICAL CVSS 9.8 Apr 7, 2025

A privilege escalation vulnerability in RUoYi v.4.8.0 allows remote attackers to gain elevated privileges through the changeStatus method. This affects all systems running the vulnerable version of RU...

CVE-2025-28408

CRITICAL CVSS 9.8 Apr 7, 2025

A privilege escalation vulnerability in RUoYi v.4.8.0 allows remote attackers to gain elevated privileges by exploiting improper validation of the deptId parameter in the selectDeptTree method. This a...

CVE-2024-46076

CRITICAL CVSS 9.8 Oct 7, 2024

RuoYi v4.7.9 and earlier contains a code injection vulnerability in the code generation feature that allows attackers to escape from comments and execute arbitrary code. This affects all systems runni...

CVE-2023-49371

CRITICAL CVSS 9.8 Dec 1, 2023

RuoYi versions up to 4.6 contain a SQL injection vulnerability in the /system/dept/edit endpoint that allows attackers to execute arbitrary SQL commands. This affects all deployments of RuoYi up to ve...

CVE-2021-28411

CRITICAL CVSS 9.8 Aug 11, 2023

This vulnerability in RuoYi's CookieRememberMeManager allows remote attackers to escalate privileges by exploiting improper deserialization of remembered user identities. Any system running the affect...

CVE-2025-70986

HIGH CVSS 7.5 Jan 23, 2026

This vulnerability in RuoYi v4.8.2 allows unauthorized attackers to bypass access controls in the selectDept function, enabling them to access sensitive department data without proper authentication. ...

CVE-2025-46175

HIGH CVSS 7.5 Nov 26, 2025

Ruoyi v4.8.0 has an incorrect access control vulnerability where the authRole method in SysUserController.java lacks a checkUserDataScope permission check. This allows authenticated users to potential...

CVE-2025-56396

HIGH CVSS 8.8 Nov 26, 2025

This vulnerability in Ruoyi 4.8.1 allows attackers to escalate privileges by exploiting a flaw where the owning department has higher rights than the active user. Attackers can gain unauthorized acces...

CVE-2025-46174

HIGH CVSS 7.5 Nov 26, 2025

Ruoyi v4.8.0 has an incorrect access control vulnerability in the resetPwd method that allows unauthorized password resets. Attackers can reset passwords of any user account without proper permission ...

CVE-2025-28407

HIGH CVSS 8.8 Apr 7, 2025

This vulnerability in RUoYi v4.8.0 allows remote attackers to escalate privileges by exploiting improper permission validation in the /edit/{dictId} endpoint. Attackers can modify data they shouldn't ...

CVE-2024-57436

HIGH CVSS 7.2 Jan 29, 2025

CVE-2024-57436 is a session ID exposure vulnerability in RuoYi v4.8.0 that allows unauthorized attackers to view admin session IDs through system monitoring. This enables session hijacking where attac...

CVE-2022-23868

HIGH CVSS 7.8 Mar 30, 2022

RuoYi v4.7.2 contains a CSV injection vulnerability in the admin module that allows attackers to embed malicious formulas in exported Excel log files. When victims open these .xlsx files in spreadshee...

CVE-2025-14856

MEDIUM CVSS 6.3 Dec 18, 2025

This vulnerability allows remote attackers to execute arbitrary code on RuoYi systems up to version 4.8.1 through code injection in the /monitor/cache/getnames endpoint. Attackers can exploit this wit...

CVE-2025-67342

MEDIUM CVSS 4.6 Dec 12, 2025

RuoYi versions 4.8.1 and earlier contain a stored cross-site scripting (XSS) vulnerability in the menu editing endpoint. Attackers with menu modification permissions can inject malicious scripts that ...

CVE-2025-10989

MEDIUM CVSS 6.3 Sep 26, 2025

This vulnerability in yangzongzhuan RuoYi up to version 4.8.1 allows attackers to bypass authorization controls by manipulating the userIds parameter in the /system/role/authUser/selectAll endpoint. A...

CVE-2025-10473

MEDIUM CVSS 6.3 Sep 15, 2025

This SQL injection vulnerability in RuoYi's blacklist handler allows attackers to execute arbitrary SQL commands on affected systems. It affects RuoYi versions up to 4.8.1 and can be exploited remotel...

CVE-2025-7907

MEDIUM CVSS 4.3 Jul 20, 2025

This vulnerability in RuoYi up to version 4.8.1 involves the use of default credentials in the Druid component configuration file. Attackers can remotely exploit this to gain unauthorized access to th...

CVE-2025-7906

MEDIUM CVSS 6.3 Jul 20, 2025

This critical vulnerability in RuoYi allows attackers to upload arbitrary files without restrictions via the uploadFile function. Remote attackers can exploit this to upload malicious files like web s...

CVE-2025-7903

MEDIUM CVSS 4.3 Jul 20, 2025

This vulnerability in RuoYi's Image Source Handler allows attackers to bypass UI layer restrictions, potentially enabling unauthorized interface manipulation. It affects RuoYi versions up to 4.8.1 and...

CVE-2025-7901

MEDIUM CVSS 4.3 Jul 20, 2025

This vulnerability allows attackers to inject malicious scripts via the configUrl parameter in Swagger UI within RuoYi systems. When exploited, it enables cross-site scripting attacks that can steal s...

CVE-2025-28401

MEDIUM CVSS 6.7 Apr 7, 2025

A privilege escalation vulnerability in RUoYi v.4.8.0 allows remote attackers to gain elevated privileges by manipulating the menuId parameter. This affects systems running the vulnerable version of R...

CVE-2024-57437

MEDIUM CVSS 6.5 Jan 29, 2025

RuoYi v4.8.0 contains a SQL injection vulnerability in the orderby parameter at the /monitor/online/list endpoint. This allows attackers to execute arbitrary SQL commands on the database. Organization...

CVE-2024-57439

MEDIUM CVSS 4.9 Jan 29, 2025

This vulnerability in RuoYi v4.8.0 allows administrators to cause a Denial of Service (DoS) by duplicating login names during password resets. The attack requires admin privileges and affects systems ...

CVE-2025-0734

MEDIUM CVSS 4.7 Jan 27, 2025

This vulnerability in RuoYi up to version 4.8.0 allows remote attackers to execute arbitrary code through deserialization in the getBeanName function of the Whitelist component. Attackers can exploit ...

CVE-2024-42900

MEDIUM CVSS 6.1 Aug 28, 2024

This cross-site scripting (XSS) vulnerability in Ruoyi's code generation tool allows attackers to inject malicious scripts via the sql parameter. When exploited, it enables session hijacking, credenti...