R
Ruoyi
Security Risk Profile
62
/100
highSecurity Risk Score
Comprehensive risk assessment based on 60 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from March 30, 2022 to present
60
Total CVEs
34
Critical+High
0
Exploited
32
Unpatched
Threat Assessment
Avg CVSS
7.2
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
32
Critical/High
Risk Level
62/100
high
Severity Distribution
Critical
19High
15Medium
20Low
6Exploit Likelihood
>50% chance
020-50%
05-20%
0<5%
11Age Distribution
Common Weaknesses (CWE)
1
XSS
13
2
SQL Injection
10
3
Code Injection
5
4
Infoleak
2
5
Malicious File Upload
1
Most Affected Products
1. Ruoyi Ruoyi86
2. yangzongzhuan RuoYi9
3. maven/com.ruoyi:ruoyi7
4. y_project RuoYi3
5. y_project/RuoYi1
Recent Vulnerabilities
See more →CVE-2026-38812
CVSS 9.8critical
Jun 15, 2026🔧 No Patch
CVE-2025-70985
CVSS 9.1critical
Jan 23, 2026🔧 No Patch
CVE-2025-70986
CVSS 7.5high
Jan 23, 2026🔧 No Patch
CVE-2024-57521
CVSS 10.0critical
Dec 23, 2025
CVE-2025-14856
CVSS 8.8high
y_project RuoYi getnames code injection
Dec 18, 2025🔧 No Patch
CVE-2025-67342
CVSS 4.6medium
Dec 12, 2025🔧 No Patch
CVE-2025-56396
CVSS 8.8high
Nov 26, 2025🔧 No Patch
CVE-2025-46174
CVSS 7.5high
Nov 26, 2025🔧 No Patch
CVE-2025-46175
CVSS 7.5high
Nov 26, 2025🔧 No Patch
CVE-2025-10989
CVSS 8.8high
yangzongzhuan RuoYi selectAll improper authorization
Sep 26, 2025🔧 No Patch
Monitor Ruoyi in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.