VendorsRYMCUforestall versions
Vulnerabilities

RYMCU Forest

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2025-12925
rymcu forest UserDicController.java deleteDic authorization
Published 2025-11-10 · Modified
9.8EPSS 0.004
CVE-2023-51804
An issue in rymcu forest v.0.02 allows a remote attacker to obtain sensitive information via manipulation of the HTTP body URL in the com.rymcu.forest.web.api.common.UploadController file.
Published 2024-01-13 · Modified
7.5EPSS 0.007
CVE-2025-12924
rymcu forest BankController.java GlobalResult authorization
Published 2025-11-10 · Modified
6.5EPSS 0.003
CVE-2025-63687
An issue was discovered in rymcu forest thru commit f782e85 (2025-09-04) in function doBefore in file src/main/java/com/rymcu/forest/core/service/security/AuthorshipAspect.java, allowing authorized attackers to delete arbitrary users posts.
Published 2025-11-07 · Analyzed
6.5EPSS 0.003
CVE-2026-2946
rymcu forest Article Content/Comments/Portfolio XssUtils.java XssUtils.replaceHtmlCode cross site scripting
Published 2026-02-22 · Analyzed
5.4EPSS 0.004
CVE-2026-2947
rymcu forest User Profile UserInfoController.java updateUserInfo cross site scripting
Published 2026-02-22 · Analyzed
5.4EPSS 0.004