Dromara Vulnerabilities and Affected Products
Vulnerabilities associated with lamp-cloud.
Products
Clear product- hertzbeat7 vulnerabilities
- lamp-cloud6 vulnerabilities
- UJCMS5 vulnerabilities
- MaxKey4 vulnerabilities
- Sa-Token4 vulnerabilities
- J2eeFAST3 vulnerabilities
- RuoYi-Vue-Plus3 vulnerabilities
- HuTool2 vulnerabilities
- dataCompare1 vulnerability
- Northstar1 vulnerability
- open-capacity-platform1 vulnerability
- warm-flow1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-19758MEDIUM | dromara lamp-cloud chunk-check endpoint FileChunkController.java path traversalA vulnerability was determined in dromara lamp-cloud up to 5.10.0. This issue affects some unknown processing of the file FileChunkController.java of the component chunk-check endpoint. Executing a manipulation of the argument Name can lead to path traversal. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet. CWE-22Aug 13, 2026 | CVSS6.9v4.0 | EPSS- | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-19757MEDIUM | Dromara lamp-cloud File-Upload Controller FileAnyoneController.java path traversalA vulnerability was found in Dromara lamp-cloud up to 5.10.0. This vulnerability affects unknown code of the file FileAnyoneController.java of the component File-Upload Controller. Performing a manipulation of the argument bucket/bizType results in path traversal. The attack can be initiated remotely. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet. CWE-22Aug 13, 2026 | CVSS6.9v4.0 | EPSS- | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-19756MEDIUM | Dromara lamp-cloud Code Generator DefGenProjectController.java path traversalA vulnerability has been found in Dromara lamp-cloud up to 5.10.0. This affects an unknown part of the file DefGenProjectController.java of the component Code Generator. Such manipulation of the argument outputDir/parent/projectPrefix leads to path traversal. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet. CWE-22Aug 13, 2026 | CVSS5.3v4.0 | EPSS- | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-69100HIGH | LAMP 5.6.2 GlueFactory Unsandboxed Groovy Script Remote Code ExecutionLAMP Rapid Development Platform through 5.6.2, fixed in commit 84b0c27, contains a remote code execution vulnerability in GlueFactory that executes unsandboxed Groovy scripts from database template fields without compilation restrictions or whitelisting. Attackers can write or influence the script field via message template endpoints to execute arbitrary Groovy code and OS commands on the backend server. CWE-94Aug 4, 2026 | CVSS8.7v4.0 | EPSS0.551% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-9498MEDIUM | Dromara lamp-cloud Message Template GroovyClassLoader.parseClass special elements used in a template engineA vulnerability has been found in Dromara lamp-cloud up to 5.6.2. Impacted is the function GroovyClassLoader.parseClass of the component Message Template Handler. Such manipulation of the argument DefMsgTemplate.content leads to improper neutralization of special elements used in a template engine. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | CVSS5.3v4.0 | EPSS0.295% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-5529MEDIUM | Dromara lamp-cloud DefUserController pageUser improper authorizationA vulnerability was detected in Dromara lamp-cloud up to 5.8.1. This vulnerability affects the function pageUser of the file /defUser/pageUser of the component DefUserController. Performing a manipulation results in improper authorization. The attack can be initiated remotely. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet. | CVSS5.3v4.0 | EPSS0.273% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |