Browse all 15 CVE security advisories affecting YunaiV. AI-powered Chinese analysis, POCs, and references for each vulnerability.
YunaiV is an open-source virtualization platform primarily used for creating and managing virtual machines and containers. Historically, it has been susceptible to multiple remote code execution vulnerabilities, cross-site scripting flaws, and privilege escalation issues, accounting for its 12 recorded CVEs. The platform's security posture has been compromised through insufficient input validation and improper access controls, leading to several high-severity exploits. Notable incidents include cases where unauthenticated attackers could execute arbitrary code or gain elevated system privileges, highlighting ongoing challenges in secure configuration and regular patch management.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-13528 | YunaiV/zhijiantianya ruoyi-vue-pro AppFileController File Upload Endpoint FileServiceImpl.java generateUploadPath path traversal — ruoyi-vue-proCWE-22 | 7.3 | High | 2026-06-29 |
| CVE-2025-10988 | YunaiV ruoyi-vue-pro transfer improper authorization — ruoyi-vue-proCWE-285 | 6.3 | Medium | 2025-09-26 |
| CVE-2025-10278 | YunaiV ruoyi-vue-pro transfer improper authorization — ruoyi-vue-proCWE-285 | 6.3 | Medium | 2025-09-12 |
| CVE-2025-10276 | YunaiV ruoyi-vue-pro transfer improper authorization — ruoyi-vue-proCWE-285 | 6.3 | Medium | 2025-09-12 |
This page lists every published CVE security advisory associated with YunaiV. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.