Products: 3
    Vulnerabilities: 70
    Known Exploited: 0
    16
    Critical Level Threats
    11
    High Level Threats
    34
    Medium Level Threats
    9
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-38812

    RuoYi v4.8.2 is vulnerable to SQL Injection via the /tool/gen/createTable endpoint. The issue affects the code generation module and may allow an authenticated attacker with administrative privileges to access sensitive database information.

    Last Modified: Jun 19, 2026
    Published: Jun 15, 2026

    CVE-2026-4564

    yangzongzhuan RuoYi Quartz Job job code injection

    Last Modified: Apr 24, 2026
    Published: Mar 22, 2026

    CVE-2025-70986

    Incorrect access control in the selectDept function of RuoYi v4.8.2 allows unauthorized attackers to arbitrarily access sensitive department data.

    Last Modified: Jan 30, 2026
    Published: Jan 23, 2026

    CVE-2025-70985

    Incorrect access control in the update function of RuoYi v4.8.2 allows unauthorized attackers to arbitrarily modify data outside of their scope.

    Last Modified: Jan 30, 2026
    Published: Jan 23, 2026

    CVE-2024-57521

    SQL Injection vulnerability in RuoYi v.4.7.9 and before allows a remote attacker to execute arbitrary code via the createTable function in SqlUtil.java.

    Last Modified: Jan 06, 2026
    Published: Dec 23, 2025
    Items Per Page
    Ruoyi Vulnerabilities & Security CVEs | CVE-DB