VendorsDromararuoyi-vue-plusany version
Vulnerabilities

Dromara Ruoyi-vue-plus any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1CVEs
CVE-2025-66916
The snailjob component in RuoYi-Vue-Plus versions 5.5.1 and earlier, interface /snail-job/workflow/check-node-expression can execute QLExpress expressions, but it does not filter user input, allowing attackers to use the File class to perform arbitrary file reading and writing.
Published 2026-01-08 · Analyzed
9.4EPSS 0.007