Renren maintains a focused product portfolio centered on communication and security applications such as Renren Talk and Renren Security, with a durable vulnerability pattern rooted in input-handling and memory-safety issues including SQL injection and buffer-boundary violations. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Renren over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-70821CRITICAL renren-secuity before v5.5.0 is vulnerable to SQL Injection in the BaseServiceImpl.java component | Mar 3, 2026 | 9.8 | 27 | NO | NO |
CVE-2012-0916HIGH Heap-based buffer overflow in RenRen Talk 2.9 allows remote attackers to execute arbitrary code via a crafted image in a chat message, as demonstrated using a PNG file. | Jan 24, 2012 | 9.3 | 27 | NO | NO |
CVE-2012-0915HIGH Integer signedness error in RenRen Talk 2.9 allows remote attackers to execute arbitrary code via crafted dimensions of a skin file, leading to a heap-based buffer overflow, as dem | Jan 24, 2012 | 9.3 | 27 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Renren.
Media articles that mention a CVE ID that affects a product developed by Renren — matched by CVE ID, not by vendor name.