Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Ruoyi

First CVE: Mar 30, 2022Active for: 4 yearsTotal CVEs: 59
42.7
VTI Score
High

Ruoyi is a modestly scoped but strategically positioned open-source enterprise management and rapid-development framework that has achieved prominence among implementation-heavy deployments, particularly in regional and enterprise contexts. The vulnerability profile concentrates across its core product lines—including Ruoyi, Ruoyi Cloud, and Ruoyi Vue variants—and skews strongly toward critical-severity outcomes, reflecting systemic weaknesses in access control, input validation, and authorization enforcement. The recurring weakness classes span improper access control, cross-site scripting, SQL injection, code injection, and missing authorization checks, which together describe a pattern of insufficient input sanitization and privilege-boundary enforcement typical of rapidly evolved web application frameworks. Defenders should treat Ruoyi deployments as high-risk when internet-facing and prioritize inventory and patching of authentication and administrative endpoints; live severity and exploitation activity are shown alongside this summary.

FAUCET AI Generated
59
Total CVEs
More Total CVEs than 99% of tracked vendors
3.9
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 95% of tracked vendors
7.4
Avg CVSS Score
Higher Avg CVSS Score than 56% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Ruoyi over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 30, 2022
4 years ago
Most Recent CVE
Jan 23, 2026
182 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (59 CVEs).

59 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2024-57521CRITICAL
SQL Injection vulnerability in RuoYi v.4.7.9 and before allows a remote attacker to execute arbitrary code via the createTable function in SqlUtil.java.
Dec 23, 202510.034NONO
CVE-2025-10473CRITICAL
A security flaw has been discovered in yangzongzhuan RuoYi up to 4.8.1. This impacts the function filterKeyword of the file /com/ruoyi/common/utils/sql/SqlUtil.java of the componen
Sep 15, 20259.834NONO
CVE-2025-70985CRITICAL
Incorrect access control in the update function of RuoYi v4.8.2 allows unauthorized attackers to arbitrarily modify data outside of their scope.
Jan 23, 20269.132NONO
CVE-2021-38241CRITICAL
Deserialization issue discovered in Ruoyi before 4.6.1 allows remote attackers to run arbitrary code via weak cipher in Shiro framework.
Dec 16, 20229.831NONO
CVE-2025-28408CRITICAL
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the selectDeptTree method of the /selectDeptTree/{deptId} endpoint does not properly validate the dept
Apr 7, 20259.830NONO
CVE-2025-28406CRITICAL
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the jobLogId parameter
Apr 7, 20259.830NONO
CVE-2022-4566CRITICAL
A vulnerability, which was classified as critical, has been found in y_project RuoYi 4.7.5. This issue affects some unknown processing of the file com/ruoyi/generator/controller/Ge
Dec 16, 20229.830NONO
CVE-2022-48114CRITICAL
RuoYi up to v4.7.5 was discovered to contain a SQL injection vulnerability via the component /tool/gen/createTable.
Feb 2, 20239.829NONO
CVE-2025-14856HIGH
A security vulnerability has been detected in y_project RuoYi up to 4.8.1. The affected element is an unknown function of the file /monitor/cache/getnames. Such manipulation of the
Dec 18, 20258.828NONO
CVE-2025-10989HIGH
A security flaw has been discovered in yangzongzhuan RuoYi up to 4.8.1. This vulnerability affects unknown code of the file /system/role/authUser/selectAll. Performing manipulation
Sep 26, 20258.828NONO
View all 59 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products59 CVEs
41%
25%
31%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (1.7%)
Network58 (98.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low55 (93.2%)
High4 (6.8%)
Unknown0 (0.0%)
User Interaction
None40 (67.8%)
Unknown0 (0.0%)
Required19 (32.2%)
Privileges Required
Low19 (32.2%)
High4 (6.8%)
None36 (61.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (59 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
1.7% of CVEs· 95th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Ruoyi.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Ruoyi — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Ruoyi's Products

View all 2 CNAs →

Top CWEs