Home/Product/ruoyi
Product

ruoyi

59 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-70986
all versions
Incorrect access control in the selectDept function of RuoYi v4.8.2 allows unauthorized attackers to arbitrarily access sensitive
7.5HIGH
CVE-2025-70985
all versions
Incorrect access control in the update function of RuoYi v4.8.2 allows unauthorized attackers to arbitrarily modify data outside o
9.1CRITICAL
CVE-2024-57521
<= 4.7.9
SQL Injection vulnerability in RuoYi v.4.7.9 and before allows a remote attacker to execute arbitrary code via the createTable fun
10.0CRITICAL
CVE-2025-14856
<= 4.8.1
A security vulnerability has been detected in y_project RuoYi up to 4.8.1. The affected element is an unknown function of the file
6.3MEDIUM
CVE-2025-67342
<= 4.8.1
RuoYi versions 4.8.1 and earlier is affected by a stored XSS vulnerability in the /system/menu/edit endpoint. While the endpoint i
4.6MEDIUM
CVE-2025-46175
all versions
Ruoyi v4.8.0 is vulnerable to Incorrect Access Control. There is a missing checkUserDataScope permission check in the authRole met
7.5HIGH
CVE-2025-56396
all versions
An issue was discovered in Ruoyi 4.8.1 allowing attackers to gain escalated privileges due to the owning department having higher
8.8HIGH
CVE-2025-46174
all versions
Ruoyi v4.8.0 vulnerable to Incorrect Access Control. There is a missing checkUserDataScope permission check in the resetPwd Method
7.5HIGH
CVE-2025-10989
<= 4.8.1
A security flaw has been discovered in yangzongzhuan RuoYi up to 4.8.1. This vulnerability affects unknown code of the file /syste
6.3MEDIUM
CVE-2025-10473
<= 4.8.1
A security flaw has been discovered in yangzongzhuan RuoYi up to 4.8.1. This impacts the function filterKeyword of the file /com/r
6.3MEDIUM
CVE-2025-10384
<= 4.8.1
A flaw has been found in yangzongzhuan RuoYi up to 4.8.1. Affected by this vulnerability is an unknown functionality of the file /
5.4MEDIUM
CVE-2025-8847
<= 4.8.1
A vulnerability was found in yangzongzhuan RuoYi up to 4.8.1. Affected by this vulnerability is the function Edit of the file /sys
3.5LOW
CVE-2025-7907
<= 4.8.1
A vulnerability was found in yangzongzhuan RuoYi up to 4.8.1. It has been classified as problematic. Affected is an unknown functi
4.3MEDIUM
CVE-2025-7906
<= 4.8.1
A vulnerability was found in yangzongzhuan RuoYi up to 4.8.1 and classified as critical. This issue affects the function uploadFil
6.3MEDIUM
CVE-2025-7903
<= 4.8.1
A vulnerability classified as problematic was found in yangzongzhuan RuoYi up to 4.8.1. Affected by this vulnerability is an unkno
4.3MEDIUM
CVE-2025-7902
<= 4.8.1
A vulnerability classified as problematic has been found in yangzongzhuan RuoYi up to 4.8.1. Affected is the function addSave of t
3.5LOW
CVE-2025-7901
<= 4.8.1
A vulnerability was found in yangzongzhuan RuoYi up to 4.8.1. It has been rated as problematic. This issue affects some unknown pr
4.3MEDIUM
CVE-2025-4819
all versions
A vulnerability classified as problematic has been found in y_project RuoYi 4.8.0. Affected is an unknown function of the file /mo
3.1LOW
CVE-2025-4537
<= 3.8.9
A vulnerability was found in yangzongzhuan RuoYi-Vue up to 3.8.9 and classified as problematic. Affected by this issue is some unk
3.1LOW
CVE-2025-28413
all versions
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the SysDictTypeController component
9.8CRITICAL
CVE-2025-28412
all versions
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the /editSave method in SysNoticeController
9.8CRITICAL
CVE-2025-28411
all versions
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the editSave method in /tool/gen/editSave
9.8CRITICAL
CVE-2025-28410
all versions
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the cancelAuthUserAll method does not properly valid
9.8CRITICAL
CVE-2025-28409
all versions
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the add method of the /add/{parentId} endpoint does
8.8HIGH
CVE-2025-28408
all versions
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the selectDeptTree method of the /selectDeptTree/{de
9.8CRITICAL
CVE-2025-28407
all versions
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the edit method of the /edit/{dictId} endpoint does
8.8HIGH
CVE-2025-28406
all versions
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the jobLogId parameter
9.8CRITICAL
CVE-2025-28405
all versions
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the changeStatus method
9.8CRITICAL
CVE-2025-28403
all versions
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the editSave method does not properly validate wheth
7.2HIGH
CVE-2025-28402
all versions
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the jobId parameter
9.8CRITICAL
CVE-2025-28401
all versions
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the menuId parameter
6.7MEDIUM
CVE-2025-28400
all versions
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the postID parameter in the edit method
6.7MEDIUM
CVE-2024-57439
all versions
An issue in the reset password interface of ruoyi v4.8.0 allows attackers with Admin privileges to cause a Denial of Service (DoS)
4.9MEDIUM
CVE-2024-57438
all versions
Insecure permissions in RuoYi v4.8.0 allows authenticated attackers to escalate privileges by assigning themselves higher level ro
5.4MEDIUM
CVE-2024-57437
all versions
RuoYi v4.8.0 was discovered to contain a SQL injection vulnerability via the orderby parameter at /monitor/online/list.
6.5MEDIUM
CVE-2024-57436
all versions
RuoYi v4.8.0 was discovered to allow unauthorized attackers to view the session ID of the admin in the system monitoring. This iss
7.2HIGH
CVE-2025-0734
<= 4.8.0
A vulnerability has been found in y_project RuoYi up to 4.8.0 and classified as critical. This vulnerability affects the function
4.7MEDIUM
CVE-2024-54762
<= 4.7.9
Ruoyi v.4.7.9 and before contains an authenticated SQL injection vulnerability. This is because the filterKeyword method does not
6.3MEDIUM
CVE-2024-46076
<= 4.7.9
RuoYi v4.7.9 and before has a security flaw that allows escaping from comments within the code generation feature, enabling the in
9.8CRITICAL
CVE-2024-9048
<= 4.7.9
A vulnerability was found in y_project RuoYi up to 4.7.9. It has been declared as problematic. Affected by this vulnerability is t
3.1LOW
CVE-2024-42900
<= 4.7.9
Ruoyi v4.7.9 and before was discovered to contain a cross-site scripting (XSS) vulnerability via the sql parameter of the createTa
6.1MEDIUM
CVE-2024-42913
all versions
RuoYi CMS v4.7.9 was discovered to contain a SQL injection vulnerability via the job_id parameter at /sasfs1.
9.8CRITICAL
CVE-2024-41599
<= 4.7.9
Cross Site Scripting vulnerability in RuoYi v.4.7.9 and before allows a remote attacker to execute arbitrary code via the file upl
6.1MEDIUM
CVE-2024-6511
<= 4.7.9
A vulnerability classified as problematic was found in y_project RuoYi up to 4.7.9. Affected by this vulnerability is the function
3.5LOW
CVE-2024-29400
all versions
An issue was discovered in RuoYi v4.5.1, allows attackers to obtain sensitive information via the status parameter.
7.5HIGH
CVE-2023-52048
all versions
RuoYi v4.7.8 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /system/notice/.
4.7MEDIUM
CVE-2023-7133
all versions
A vulnerability was found in y_project RuoYi 4.7.8. It has been declared as problematic. This vulnerability affects unknown code o
4.3MEDIUM
CVE-2023-49371
<= 4.6.0
RuoYi up to v4.6 was discovered to contain a SQL injection vulnerability via /system/dept/edit.
9.8CRITICAL
CVE-2021-28411
all versions
An issue was discovered in getRememberedSerializedIdentity function in CookieRememberMeManager class in lerry903 RuoYi version 3.4
9.8CRITICAL
CVE-2023-3815
<= 4.7.7
A vulnerability, which was classified as problematic, has been found in y_project RuoYi up to 4.7.7. Affected by this issue is the
3.5LOW
CVE-2023-3163
<= 4.7.7
A vulnerability was found in y_project RuoYi up to 4.7.7. It has been classified as problematic. Affected is the function filterKe
3.5LOW
CVE-2023-27025
<= 4.7.6
An arbitrary file download vulnerability in the background management module of RuoYi v4.7.6 and below allows attackers to downloa
7.5HIGH
CVE-2022-48114
<= 4.7.5
RuoYi up to v4.7.5 was discovered to contain a SQL injection vulnerability via the component /tool/gen/createTable.
9.8CRITICAL
CVE-2021-38241
< 4.6.1
Deserialization issue discovered in Ruoyi before 4.6.1 allows remote attackers to run arbitrary code via weak cipher in Shiro fram
9.8CRITICAL
CVE-2022-4566
all versions
A vulnerability, which was classified as critical, has been found in y_project RuoYi 4.7.5. This issue affects some unknown proces
5.5MEDIUM
CVE-2022-4348
all versions
A vulnerability was found in y_project RuoYi-Cloud. It has been rated as problematic. Affected by this issue is some unknown funct
3.5LOW
CVE-2022-32065
<= 4.7.3
An arbitrary file upload vulnerability in the background management module of RuoYi v4.7.3 and below allows attackers to execute a
5.4MEDIUM
CVE-2022-23869
all versions
In RuoYi v4.7.2 through the WebUI, user test1 does not have permission to reset the password of user test3, but the password of us
6.5MEDIUM
CVE-2022-23868
all versions
RuoYi v4.7.2 contains a CSV injection vulnerability through ruoyi-admin when a victim opens .xlsx log file.
7.8HIGH
threatengine.sh