Vulnerabilities (CVE)

Filtered by vendor Ruoyi Subscribe
Total 43 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-32065 1 Ruoyi 1 Ruoyi 2022-07-26 3.5 LOW 5.4 MEDIUM
An arbitrary file upload vulnerability in the background management module of RuoYi v4.7.3 and below allows attackers to execute arbitrary code via a crafted HTML file.
CVE-2022-23869 1 Ruoyi 1 Ruoyi 2022-04-04 4.0 MEDIUM 6.5 MEDIUM
In RuoYi v4.7.2 through the WebUI, user test1 does not have permission to reset the password of user test3, but the password of user test3 can be reset through the /system/user/resetPwd request.
CVE-2022-23868 1 Ruoyi 1 Ruoyi 2022-04-04 6.8 MEDIUM 7.8 HIGH
RuoYi v4.7.2 contains a CSV injection vulnerability through ruoyi-admin when a victim opens .xlsx log file.