Dromara Vulnerabilities and Affected Products
Vulnerabilities associated with RuoYi-Vue-Plus.
Products
Clear product- hertzbeat7 vulnerabilities
- lamp-cloud6 vulnerabilities
- UJCMS5 vulnerabilities
- MaxKey4 vulnerabilities
- Sa-Token4 vulnerabilities
- J2eeFAST3 vulnerabilities
- RuoYi-Vue-Plus3 vulnerabilities
- HuTool2 vulnerabilities
- dataCompare1 vulnerability
- Northstar1 vulnerability
- open-capacity-platform1 vulnerability
- warm-flow1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-58176HIGH | RuoYi-Vue-Plus - Missing Authorization on Workflow Task Management EndpointsRuoYi-Vue-Plus through 5.6.2, fixed in commit 88d03d9, exposes workflow task management endpoints under /workflow/task (FlwTaskController) without any permission check: the controller declares no class-level or method-level authorization annotation, so the endpoints are gated only by global authentication. Any authenticated user, regardless of assigned role, can therefore reassign workflow approval tasks to arbitrary users via updateAssignee (defeating segregation of duties in the approval proce… CWE-862Jun 30, 2026 | CVSS7.1v4.0 | EPSS0.264% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-2819MEDIUM | Dromara RuoYi-Vue-Plus Workflow deleteByInstanceIds SaServletFilter authorizationA vulnerability was identified in Dromara RuoYi-Vue-Plus up to 5.5.3. This vulnerability affects the function SaServletFilter of the file /workflow/instance/deleteByInstanceIds of the component Workflow Module. The manipulation leads to missing authorization. The attack may be initiated remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. | CVSS5.3v4.0 | EPSS0.253% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-6925MEDIUM | Dromara RuoYi-Vue-Plus Mail MailController.java path traversalA vulnerability has been found in Dromara RuoYi-Vue-Plus 5.4.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /src/main/java/org/dromara/demo/controller/MailController.java of the component Mail Handler. The manipulation of the argument filePath leads to path traversal. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in an… CWE-22Jun 30, 2025 | CVSS6.9v4.0 | EPSS0.864% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |