Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Dromara — Vulnerabilities & Security Advisories 48

Browse all 48 CVE security advisories affecting Dromara. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Dromara is an open-source ecosystem primarily focused on providing rapid development frameworks and enterprise-level solutions for Java-based applications. Its core offerings include modular platforms designed to streamline backend development, often serving as the foundation for various commercial and internal enterprise systems. Security audits have identified twenty-six Common Vulnerabilities and Exposures (CVEs) associated with components within this ecosystem. Historically, these vulnerabilities predominantly manifest as Remote Code Execution (RCE) flaws, often stemming from insecure deserialization or improper input validation in underlying libraries. Additionally, instances of Cross-Site Scripting (XSS) and privilege escalation vulnerabilities have been documented, typically arising from misconfigured access controls or outdated dependencies. While no single catastrophic incident has defined the project’s public history, the accumulation of CVEs highlights the necessity for rigorous dependency management and regular patching. Developers utilizing Dromara-based architectures must prioritize updating framework versions to mitigate these known risks and ensure system integrity.

CVE ID Title CVSS Severity Published
CVE-2026-94536 lamp-cloud through 5.10.0 Unauthorized Information Disclosure via /anyone/visible/resource — lamp-cloud CWE-639 4.3 Medium 2026-09-21
CVE-2026-94535 lamp-cloud through 5.10.0 Unauthorized Notification Deletion — lamp-cloud CWE-639 7.1 High 2026-09-21
CVE-2026-94534 lamp-cloud through 5.10.0 Unauthorized Profile Modification via PUT endpoints — lamp-cloud CWE-639 7.1 High 2026-09-21
CVE-2026-94533 lamp-cloud through 5.10.0 Unauthorized File Download via /anyone/file — lamp-cloud CWE-639 6.5 Medium 2026-09-21
CVE-2026-94532 lamp-cloud through 5.10.0 Unauthorized User Profile Access via getUserInfoById — lamp-cloud CWE-639 6.5 Medium 2026-09-21
CVE-2026-93961 Dromara UJCMS UserController UserController.java usernameExist improper authorization — UJCMS CWE-285 5.3 Medium 2026-09-20
CVE-2026-92993 Dromara mayfly-go Machine Script Feature machine_script.go RunMachineScript os command injection — mayfly-go CWE-78 6.3 Medium 2026-09-17
CVE-2026-92992 Dromara mayfly-go AI Assistant ai.go authorization — mayfly-go CWE-862 6.3 Medium 2026-09-17
CVE-2026-91996 lamp-cloud through 5.10.0 Missing Authentication for JVM Properties Endpoint — lamp-cloud CWE-306 7.5 High 2026-09-15
CVE-2026-91993 Jpom through 2.11.12 Workspace Isolation Bypass via /build/branch-list — Jpom CWE-639 4.3 Medium 2026-09-15
CVE-2026-90510 dromara orion-visor HostKeyServiceImpl.java HostKeyServiceImpl.encryptKey hard-coded key — orion-visor CWE-321 8.3 High 2026-09-13
CVE-2026-90509 dromara orion-visor ExposeApiAspect.java ExposeApiAspect.beforeExposeApi hard-coded credentials — orion-visor CWE-798 7.3 High 2026-09-13
CVE-2026-78140 Dromara UJCMS web-file-template Endpoint WebFileTemplateController.java update special elements in template engine — UJCMS CWE-1336 4.7 Medium 2026-08-23
CVE-2026-77795 Dromara RuoYi-Vue-Plus Workflow Endpoint TestLeaveController improper authorization — RuoYi-Vue-Plus CWE-285 6.3 Medium 2026-08-21
CVE-2026-19758 dromara lamp-cloud chunk-check endpoint FileChunkController.java path traversal — lamp-cloud CWE-22 7.3 High 2026-08-13
CVE-2026-19757 Dromara lamp-cloud File-Upload Controller FileAnyoneController.java path traversal — lamp-cloud CWE-22 7.3 High 2026-08-13
CVE-2026-19756 Dromara lamp-cloud Code Generator DefGenProjectController.java path traversal — lamp-cloud CWE-22 6.3 Medium 2026-08-13
CVE-2026-69102 MaxKey Hard-coded JWT Secret Unauthorized Access via /login/jwt/trust — MaxKey CWE-798 9.8 Critical 2026-08-11
CVE-2026-69100 LAMP 5.6.2 GlueFactory Unsandboxed Groovy Script Remote Code Execution — lamp-cloud CWE-94 8.8 High 2026-08-04
CVE-2026-67345 MaxKey 4.1.12 DefaultRedirectResolver OAuth Authorization Code Theft — MaxKey CWE-183 8.1 High 2026-07-30
CVE-2026-58176 RuoYi-Vue-Plus - Missing Authorization on Workflow Task Management Endpoints — RuoYi-Vue-Plus CWE-862 6.5 Medium 2026-06-30
CVE-2026-9498 Dromara lamp-cloud Message Template GroovyClassLoader.parseClass special elements used in a template engine — lamp-cloud CWE-1336 6.3 Medium 2026-05-25
CVE-2026-7699 Dromara MaxKey StrUtils.java StrUtils.checkSqlInjection sql injection — MaxKey CWE-89 6.3 Medium 2026-05-03
CVE-2026-6125 Dromara warm-flow Workflow Definition save-json SpelHelper.parseExpression code injection — warm-flow CWE-94 6.3 Medium 2026-04-12
CVE-2026-5529 Dromara lamp-cloud DefUserController pageUser improper authorization — lamp-cloud CWE-285 4.3 Medium 2026-04-05
CVE-2026-2954 Dromara UJCMS ImportDataController import-channel importChanel injection — UJCMS CWE-74 6.3 Medium 2026-02-22
CVE-2026-2953 Dromara UJCMS Template WebFileTemplateController.delete deleteDirectory path traversal — UJCMS CWE-22 5.4 Medium 2026-02-22
CVE-2026-2819 Dromara RuoYi-Vue-Plus Workflow deleteByInstanceIds SaServletFilter authorization — RuoYi-Vue-Plus CWE-862 6.3 Medium 2026-02-20
CVE-2025-15222 Dromara Sa-Token SaSerializerTemplateForJdkUseBase64.java ObjectInputStream.readObject deserialization — Sa-Token CWE-502 5.0 Medium 2025-12-30
CVE-2025-15117 Dromara Sa-Token SaJdkSerializer.java ObjectInputStream.readObject deserialization — Sa-Token CWE-502 3.1 Low 2025-12-28

This page lists every published CVE security advisory associated with Dromara. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.