Lostvip maintains the RuoYi-Go administrative framework, a narrowly scoped but notably represented product in the vulnerability landscape. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and cluster consistently around output injection, SQL injection, and path-traversal flaws that reflect the data-handling and input-validation demands of web administrative interfaces. Defenders should prioritize patching instances of this framework, particularly those exposed to untrusted networks; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Lostvip over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-10218CRITICAL A flaw has been found in lostvip-com ruoyi-go 2.1. This affects the function SelectListPage of the file modules/system/dao/SysRoleDao.go of the component Background Management Page | Sep 10, 2025 | 9.8 | 34 | NO | NO |
CVE-2025-9413CRITICAL A flaw has been found in lostvip-com ruoyi-go up to 2.1. This impacts the function SelectListByPage of the file modules/system/system_router.go. This manipulation of the argument o | Aug 25, 2025 | 9.8 | 34 | NO | NO |
CVE-2025-9411CRITICAL A security vulnerability has been detected in lostvip-com ruoyi-go up to 2.1. The impacted element is the function SelectPageList of the file modules/system/service/LoginInforServi | Aug 25, 2025 | 9.8 | 34 | NO | NO |
CVE-2025-9410CRITICAL A weakness has been identified in lostvip-com ruoyi-go up to 2.1. The affected element is the function SelectListByPage of the file modules/system/dao/GenTableDao.go. Executing man | Aug 25, 2025 | 9.8 | 33 | NO | NO |
CVE-2025-9412CRITICAL A vulnerability was detected in lostvip-com ruoyi-go up to 2.1. This affects the function SelectListByPage of the file modules/system/dao/DictDataDao.go. The manipulation of the ar | Aug 25, 2025 | 9.8 | 30 | NO | NO |
CVE-2025-9409MEDIUM A security flaw has been discovered in lostvip-com ruoyi-go up to 2.1. Impacted is the function DownloadTmp/DownloadUpload of the file modules/system/controller/CommonController.go | Aug 25, 2025 | 6.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Lostvip.
Media articles that mention a CVE ID that affects a product developed by Lostvip — matched by CVE ID, not by vendor name.