Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Dromara — Vulnerabilities & Security Advisories 48

Browse all 48 CVE security advisories affecting Dromara. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Dromara is an open-source ecosystem primarily focused on providing rapid development frameworks and enterprise-level solutions for Java-based applications. Its core offerings include modular platforms designed to streamline backend development, often serving as the foundation for various commercial and internal enterprise systems. Security audits have identified twenty-six Common Vulnerabilities and Exposures (CVEs) associated with components within this ecosystem. Historically, these vulnerabilities predominantly manifest as Remote Code Execution (RCE) flaws, often stemming from insecure deserialization or improper input validation in underlying libraries. Additionally, instances of Cross-Site Scripting (XSS) and privilege escalation vulnerabilities have been documented, typically arising from misconfigured access controls or outdated dependencies. While no single catastrophic incident has defined the project’s public history, the accumulation of CVEs highlights the necessity for rigorous dependency management and regular patching. Developers utilizing Dromara-based architectures must prioritize updating framework versions to mitigate these known risks and ensure system integrity.

Found 12 results / 48 Clear Filters
CVE ID Title CVSS Severity Published
CVE-2026-94536 lamp-cloud through 5.10.0 Unauthorized Information Disclosure via /anyone/visible/resource — lamp-cloud CWE-639 4.3 Medium 2026-09-21
CVE-2026-94535 lamp-cloud through 5.10.0 Unauthorized Notification Deletion — lamp-cloud CWE-639 7.1 High 2026-09-21
CVE-2026-94534 lamp-cloud through 5.10.0 Unauthorized Profile Modification via PUT endpoints — lamp-cloud CWE-639 7.1 High 2026-09-21
CVE-2026-94533 lamp-cloud through 5.10.0 Unauthorized File Download via /anyone/file — lamp-cloud CWE-639 6.5 Medium 2026-09-21
CVE-2026-94532 lamp-cloud through 5.10.0 Unauthorized User Profile Access via getUserInfoById — lamp-cloud CWE-639 6.5 Medium 2026-09-21
CVE-2026-91996 lamp-cloud through 5.10.0 Missing Authentication for JVM Properties Endpoint — lamp-cloud CWE-306 7.5 High 2026-09-15
CVE-2026-19758 dromara lamp-cloud chunk-check endpoint FileChunkController.java path traversal — lamp-cloud CWE-22 7.3 High 2026-08-13
CVE-2026-19757 Dromara lamp-cloud File-Upload Controller FileAnyoneController.java path traversal — lamp-cloud CWE-22 7.3 High 2026-08-13
CVE-2026-19756 Dromara lamp-cloud Code Generator DefGenProjectController.java path traversal — lamp-cloud CWE-22 6.3 Medium 2026-08-13
CVE-2026-69100 LAMP 5.6.2 GlueFactory Unsandboxed Groovy Script Remote Code Execution — lamp-cloud CWE-94 8.8 High 2026-08-04
CVE-2026-9498 Dromara lamp-cloud Message Template GroovyClassLoader.parseClass special elements used in a template engine — lamp-cloud CWE-1336 6.3 Medium 2026-05-25
CVE-2026-5529 Dromara lamp-cloud DefUserController pageUser improper authorization — lamp-cloud CWE-285 4.3 Medium 2026-04-05

This page lists every published CVE security advisory associated with Dromara. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.