Ruoyi is a modestly scoped but strategically positioned open-source enterprise management and rapid-development framework that has achieved prominence among implementation-heavy deployments, particularly in regional and enterprise contexts. The vulnerability profile concentrates across its core product lines—including Ruoyi, Ruoyi Cloud, and Ruoyi Vue variants—and skews strongly toward critical-severity outcomes, reflecting systemic weaknesses in access control, input validation, and authorization enforcement. The recurring weakness classes span improper access control, cross-site scripting, SQL injection, code injection, and missing authorization checks, which together describe a pattern of insufficient input sanitization and privilege-boundary enforcement typical of rapidly evolved web application frameworks. Defenders should treat Ruoyi deployments as high-risk when internet-facing and prioritize inventory and patching of authentication and administrative endpoints; live severity and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ruoyi over time
Signals from CVEs in this vendor scope (59 CVEs).
59 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-57521CRITICAL SQL Injection vulnerability in RuoYi v.4.7.9 and before allows a remote attacker to execute arbitrary code via the createTable function in SqlUtil.java. | Dec 23, 2025 | 10.0 | 34 | NO | NO |
CVE-2025-10473CRITICAL A security flaw has been discovered in yangzongzhuan RuoYi up to 4.8.1. This impacts the function filterKeyword of the file /com/ruoyi/common/utils/sql/SqlUtil.java of the componen | Sep 15, 2025 | 9.8 | 34 | NO | NO |
CVE-2025-70985CRITICAL Incorrect access control in the update function of RuoYi v4.8.2 allows unauthorized attackers to arbitrarily modify data outside of their scope. | Jan 23, 2026 | 9.1 | 32 | NO | NO |
CVE-2021-38241CRITICAL Deserialization issue discovered in Ruoyi before 4.6.1 allows remote attackers to run arbitrary code via weak cipher in Shiro framework. | Dec 16, 2022 | 9.8 | 31 | NO | NO |
CVE-2025-28408CRITICAL An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the selectDeptTree method of the /selectDeptTree/{deptId} endpoint does not properly validate the dept | Apr 7, 2025 | 9.8 | 30 | NO | NO |
CVE-2025-28406CRITICAL An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the jobLogId parameter | Apr 7, 2025 | 9.8 | 30 | NO | NO |
CVE-2022-4566CRITICAL A vulnerability, which was classified as critical, has been found in y_project RuoYi 4.7.5. This issue affects some unknown processing of the file com/ruoyi/generator/controller/Ge | Dec 16, 2022 | 9.8 | 30 | NO | NO |
CVE-2022-48114CRITICAL RuoYi up to v4.7.5 was discovered to contain a SQL injection vulnerability via the component /tool/gen/createTable. | Feb 2, 2023 | 9.8 | 29 | NO | NO |
CVE-2025-14856HIGH A security vulnerability has been detected in y_project RuoYi up to 4.8.1. The affected element is an unknown function of the file /monitor/cache/getnames. Such manipulation of the | Dec 18, 2025 | 8.8 | 28 | NO | NO |
CVE-2025-10989HIGH A security flaw has been discovered in yangzongzhuan RuoYi up to 4.8.1. This vulnerability affects unknown code of the file /system/role/authUser/selectAll. Performing manipulation | Sep 26, 2025 | 8.8 | 28 | NO | NO |
Signals from CVEs in this vendor scope (59 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ruoyi.
Media articles that mention a CVE ID that affects a product developed by Ruoyi — matched by CVE ID, not by vendor name.