Roothub
Vendor:
First CVE: Apr 12, 2022 · Active for 4 years
8
Total CVEs
More Total CVEs than 49% of tracked products
2.7
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
8.2
Avg CVSS
Higher Avg CVSS than 87% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Roothub over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 12, 2022
4 years ago
Most Recent CVE
Jul 26, 2025
364 days ago
CVE Severity & Scoring
Roothub8 CVEs
38%
13%
50%
All CVEs352,708 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network8 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None6 (75.0%)
Unknown0 (0.0%)
Required2 (25.0%)
Privileges Required
Low3 (37.5%)
High0 (0.0%)
None5 (62.5%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-27473CRITICAL SQL injection vulnerability in Topics Searching feature of Roothub 2.6.0 allows unauthorized attackers to execute arbitrary SQL commands via the "s" parameter remotely. | Apr 12, 2022 | 9.8 | 31 | NO | NO |
CVE-2024-33120CRITICAL Roothub v2.5 was discovered to contain an arbitrary file upload vulnerability via the customPath parameter in the upload() function. This vulnerability allows attackers to execute | May 7, 2024 | 9.8 | 29 | NO | NO |
CVE-2022-27472CRITICAL SQL injection vulnerability in Topics Counting feature of Roothub 2.6.0 allows unauthorized attackers to execute arbitrary SQL commands via the "s" parameter remotely. | Apr 12, 2022 | 9.8 | 29 | NO | NO |
CVE-2022-28052HIGH Directory Traversal vulnerability in file cn/roothub/store/FileSystemStorageService in function store in Roothub 2.6.0 allows remote attackers with low privlege to arbitrarily uplo | Apr 13, 2022 | 8.0 | 27 | NO | NO |
CVE-2024-33124CRITICAL Roothub v2.6 was discovered to contain a SQL injection vulnerability via the nodeTitle parameter in the parentNode() function.. | May 7, 2024 | 9.8 | 26 | NO | NO |
CVE-2025-8211MEDIUM A vulnerability was found in Roothub up to 2.6. It has been declared as problematic. Affected by this vulnerability is the function Edit of the file src/main/java/cn/roothub/web/ad | Jul 26, 2025 | 6.1 | 19 | NO | NO |
CVE-2024-33122MEDIUM Roothub v2.6 was discovered to contain a SQL injection vulnerability via the topic parameter in the list() function. | May 7, 2024 | 6.3 | 19 | NO | NO |
CVE-2024-33121MEDIUM Roothub v2.6 was discovered to contain a SQL injection vulnerability via the 's' parameter in the search() function. | May 6, 2024 | 6.3 | 19 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (8 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (8 CVEs).
Media Mentions
Signals from CVEs in this product scope (8 CVEs).
Top CNAs Publishing CVEs For Roothub
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.6.0 | 6 | 8.3 | 1.0% | 0 | 0 |
| 2.5.0 | 1 | 9.8 | 0.8% | 0 | 0 |