Rymcu's vulnerability footprint centers on Forest, a focused software product where vulnerabilities skew toward serious outcomes and concentrate in application-layer weakness classes. The recurring exposure reflects authorization and input-handling weaknesses—including improper access control, code injection, cross-site scripting, and server-side request forgery—that are characteristic of web-facing applications. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Rymcu over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-12925CRITICAL A security flaw has been discovered in rymcu forest up to de53ce79db9faa2efc4e79ce1077a302c42a1224. Impacted is the function getAll/addDic/getAllDic/deleteDic of the file src/main/ | Nov 10, 2025 | 9.8 | 31 | NO | NO |
CVE-2025-12924MEDIUM A vulnerability was identified in rymcu forest up to de53ce79db9faa2efc4e79ce1077a302c42a1224. This issue affects the function GlobalResult of the file src/main/java/com/rymcu/fore | Nov 10, 2025 | 6.5 | 22 | NO | NO |
CVE-2025-63687MEDIUM An issue was discovered in rymcu forest thru commit f782e85 (2025-09-04) in function doBefore in file src/main/java/com/rymcu/forest/core/service/security/AuthorshipAspect.java, al | Nov 7, 2025 | 6.5 | 22 | NO | NO |
CVE-2026-2947MEDIUM A vulnerability was detected in rymcu forest up to 0.0.5. This affects the function updateUserInfo of the file - src/main/java/com/rymcu/forest/web/api/user/UserInfoController.java | Feb 22, 2026 | 5.4 | 20 | NO | NO |
CVE-2023-51804HIGH An issue in rymcu forest v.0.02 allows a remote attacker to obtain sensitive information via manipulation of the HTTP body URL in the com.rymcu.forest.web.api.common.UploadControll | Jan 13, 2024 | 7.5 | 20 | NO | NO |
CVE-2026-2946MEDIUM A security vulnerability has been detected in rymcu forest up to 0.0.5. Affected by this issue is the function XssUtils.replaceHtmlCode of the file src/main/java/com/rymcu/forest/u | Feb 22, 2026 | 5.4 | 19 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Rymcu.
Media articles that mention a CVE ID that affects a product developed by Rymcu — matched by CVE ID, not by vendor name.