All 4 CVE vulnerabilities found in RuoYi-Vue-Plus, with AI-generated Chinese analysis, references, and POCs.
Vendor: Dromara
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-77795 | Dromara RuoYi-Vue-Plus Workflow Endpoint TestLeaveController improper authorization CWE-285 | 6.3 | Medium | 2026-08-21 |
| CVE-2026-58176 | RuoYi-Vue-Plus - Missing Authorization on Workflow Task Management Endpoints CWE-862 | 6.5 | Medium | 2026-06-30 |
| CVE-2026-2819 | Dromara RuoYi-Vue-Plus Workflow deleteByInstanceIds SaServletFilter authorization CWE-862 | 6.3 | Medium | 2026-02-20 |
| CVE-2025-6925 | Dromara RuoYi-Vue-Plus Mail MailController.java path traversal CWE-22 | 5.3 | Medium | 2025-06-30 |
All 4 known CVE vulnerabilities affecting RuoYi-Vue-Plus with full Chinese analysis, references, and POCs where available.