Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

lamp-cloud — Vulnerabilities & Security Advisories 12

All 12 CVE vulnerabilities found in lamp-cloud, with AI-generated Chinese analysis, references, and POCs.

Vendor: Dromara

CVE ID Title CVSS Severity Published
CVE-2026-94536 lamp-cloud through 5.10.0 Unauthorized Information Disclosure via /anyone/visible/resource CWE-639 4.3 Medium 2026-09-21
CVE-2026-94535 lamp-cloud through 5.10.0 Unauthorized Notification Deletion CWE-639 7.1 High 2026-09-21
CVE-2026-94534 lamp-cloud through 5.10.0 Unauthorized Profile Modification via PUT endpoints CWE-639 7.1 High 2026-09-21
CVE-2026-94533 lamp-cloud through 5.10.0 Unauthorized File Download via /anyone/file CWE-639 6.5 Medium 2026-09-21
CVE-2026-94532 lamp-cloud through 5.10.0 Unauthorized User Profile Access via getUserInfoById CWE-639 6.5 Medium 2026-09-21
CVE-2026-91996 lamp-cloud through 5.10.0 Missing Authentication for JVM Properties Endpoint CWE-306 7.5 High 2026-09-15
CVE-2026-19758 dromara lamp-cloud chunk-check endpoint FileChunkController.java path traversal CWE-22 7.3 High 2026-08-13
CVE-2026-19757 Dromara lamp-cloud File-Upload Controller FileAnyoneController.java path traversal CWE-22 7.3 High 2026-08-13
CVE-2026-19756 Dromara lamp-cloud Code Generator DefGenProjectController.java path traversal CWE-22 6.3 Medium 2026-08-13
CVE-2026-69100 LAMP 5.6.2 GlueFactory Unsandboxed Groovy Script Remote Code Execution CWE-94 8.8 High 2026-08-04
CVE-2026-9498 Dromara lamp-cloud Message Template GroovyClassLoader.parseClass special elements used in a template engine CWE-1336 6.3 Medium 2026-05-25
CVE-2026-5529 Dromara lamp-cloud DefUserController pageUser improper authorization CWE-285 4.3 Medium 2026-04-05

All 12 known CVE vulnerabilities affecting lamp-cloud with full Chinese analysis, references, and POCs where available.