Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

platform — Vulnerabilities & Security Advisories 61

All 61 CVE vulnerabilities found in platform, with AI-generated Chinese analysis, references, and POCs.

This page provides a comprehensive aggregation of security vulnerabilities related to the platform product. It serves as a centralized resource for tracking security weaknesses, vendor advisories, and historical incident data associated with this specific software ecosystem. The collection focuses on identifying, categorizing, and documenting security flaws that may impact the integrity, confidentiality, or availability of the platform infrastructure. The vulnerability database on this page covers a wide spectrum of issue types, including but not limited to injection flaws, broken access control, security misconfigurations, and cross-site scripting. The data encompasses records spanning the last three years, ensuring that both legacy and recent security concerns are accessible for analysis. This timeframe allows users to observe trends in vulnerability disclosure and patch adoption over time. Visitors can use this resource to track specific vendor advisories and understand the context of each weakness class within the platform environment. By examining the detailed history of vulnerabilities, stakeholders can assess the overall security posture of the product and identify patterns in reported issues. This information supports informed decision-making regarding system updates, remediation efforts, and risk management strategies. The aggregated data is structured to facilitate efficient searching and filtering by severity, status, and publication date, enabling security professionals to conduct thorough due diligence and maintain robust security practices for the platform.

Vendor: orchidsoftware

CVE ID Title CVSS Severity Published
CVE-2026-56769 Huly Platform - Server-Side Request Forgery via /import Endpoint CWE-918 8.5 High 2026-06-25
CVE-2026-7778 runZero Platform dashboard configuration exposure CWE-269 5.0 Medium 2026-05-05
CVE-2026-5384 runZero Platform incorrect credential scope CWE-863 5.8 Medium 2026-04-07
CVE-2026-5382 runZero Platform MCP endpoint information leak CWE-863 3.0 Low 2026-04-07
CVE-2026-5381 runZero Platform task information leak CWE-863 2.2 Low 2026-04-07
CVE-2026-5380 runZero Platform cleartext secret exposure CWE-863 5.3 Medium 2026-04-07
CVE-2026-5379 runZero Platform MCP certification information leak CWE-863 3.0 Low 2026-04-07
CVE-2026-5378 runZero Platform user creation leak CWE-863 5.8 Medium 2026-04-07
CVE-2026-5376 runZero Platform session timeout failure CWE-613 5.9 Medium 2026-04-07
CVE-2026-5375 runZero Platform API credential information leak CWE-200 2.7 Low 2026-04-07
CVE-2026-5374 runZero Platform MCP information leak CWE-863 5.8 Medium 2026-04-07
CVE-2026-5373 runZero Platform superuser privilege escalation CWE-269 8.1 High 2026-04-07
CVE-2026-5372 runZero Platform SQL injection in saved queries CWE-89 6.4 Medium 2026-04-07
CVE-2025-13265 lsfusion platform ZipUtils.java unpackFile path traversal CWE-22 6.3 Medium 2025-11-17
CVE-2025-13262 lsfusion platform UploadFileRequestHandler.java UploadFileRequestHandler path traversal CWE-22 7.3 High 2025-11-17
CVE-2025-13261 lsfusion platform DownloadFileRequestHandler.java DownloadFileRequestHandler path traversal CWE-22 5.3 Medium 2025-11-17
CVE-2025-10822 fuyang_lipengjun platform queryAll SysSmsLogController improper authorization CWE-285 4.3 Medium 2025-09-22
CVE-2025-10821 fuyang_lipengjun platform queryAll TopicCategoryController improper authorization CWE-285 4.3 Medium 2025-09-22
CVE-2025-10820 fuyang_lipengjun platform queryAll TopicController improper authorization CWE-285 4.3 Medium 2025-09-22
CVE-2025-10819 fuyang_lipengjun platform queryAll UserCouponController improper authorization CWE-285 4.3 Medium 2025-09-22
CVE-2025-10676 fuyang_lipengjun platform queryAll BrandController improper authorization CWE-285 4.3 Medium 2025-09-18
CVE-2025-10675 fuyang_lipengjun platform queryAll AttributeController improper authorization CWE-285 4.3 Medium 2025-09-18
CVE-2025-10674 fuyang_lipengjun platform queryAll AttributeCategoryController improper authorization CWE-285 4.3 Medium 2025-09-18
CVE-2025-10086 fuyang_lipengjun platform AdPositionController queryAll improper authorization CWE-285 6.3 Medium 2025-09-08
CVE-2025-9936 fuyang_lipengjun platform queryAll AdController improper authorization CWE-285 4.3 Medium 2025-09-03
CVE-2015-10143 Platform < 1.4.4 - Missing Authorization to Unauthenticated Arbitrary Options Update CWE-862 9.8 Critical 2025-07-25
CVE-2025-7936 fuyang_lipengjun platform ScheduleJobLogController.java queryPage sql injection CWE-89 6.3 Medium 2025-07-21
CVE-2025-7935 fuyang_lipengjun platform SysLogController.java SysLogController sql injection CWE-89 6.3 Medium 2025-07-21
CVE-2025-7934 fuyang_lipengjun platform ScheduleJobController.java queryPage sql injection CWE-89 6.3 Medium 2025-07-21
CVE-2024-51992 Method Exposure Vulnerability in Modals in orchid/platform CWE-749 4.1 Medium 2024-11-11

All 61 known CVE vulnerabilities affecting platform with full Chinese analysis, references, and POCs where available.