VendorsDromararuoyi-vue-plusall versions
Vulnerabilities

Dromara Ruoyi-vue-plus

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2025-66916
The snailjob component in RuoYi-Vue-Plus versions 5.5.1 and earlier, interface /snail-job/workflow/check-node-expression can execute QLExpress expressions, but it does not filter user input, allowing attackers to use the File class to perform arbitrary file reading and writing.
Published 2026-01-08 · Analyzed
9.4EPSS 0.007
CVE-2025-6925
Dromara RuoYi-Vue-Plus Mail MailController.java path traversal
Published 2025-06-30 · Analyzed
9.1EPSS 0.010