📦 Ruoyi Vue Pro

by Iocoder

🔍 What is Ruoyi Vue Pro?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-10988

MEDIUM CVSS 6.3 Sep 26, 2025

This vulnerability allows unauthorized access to the business transfer functionality in YunaiV ruoyi-vue-pro CRM systems. Attackers can remotely exploit this improper authorization flaw to perform una...

CVE-2025-10278

MEDIUM CVSS 6.3 Sep 12, 2025

This vulnerability allows unauthorized contact transfer in YunaiV ruoyi-vue-pro CRM systems. Attackers can remotely manipulate contact ownership without proper authorization checks. Organizations usin...

CVE-2025-10276

MEDIUM CVSS 6.3 Sep 12, 2025

This vulnerability allows unauthorized users to transfer CRM contracts to different owners due to improper authorization checks in the YunaiV ruoyi-vue-pro application. Remote attackers can exploit th...

CVE-2025-2744

MEDIUM CVSS 5.4 Mar 25, 2025

This critical vulnerability in ruoyi-vue-pro 2.4.1 allows attackers to perform path traversal attacks through the material upload interface. By manipulating file upload parameters, attackers can poten...

CVE-2025-2742

MEDIUM CVSS 5.4 Mar 25, 2025

This critical vulnerability in ruoyi-vue-pro 2.4.1 allows remote attackers to perform path traversal attacks through the material upload interface. By manipulating file upload parameters, attackers ca...

CVE-2025-2708

MEDIUM CVSS 5.4 Mar 24, 2025

This critical vulnerability in zhijiantianya ruoyi-vue-pro 2.4.1 allows remote attackers to perform path traversal attacks via the /admin-api/infra/file/upload endpoint. Attackers can potentially writ...