Vendor
Dromara vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 20 vulnerabilities in Dromara: 0 in the last 7 days and 17 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2026-92993, was published on 17 September 2026. 2 technologies have a page of their own.
- Last 7 days
- 0
- Last 90 days
- 17
- Critical, all time
- 1
- Exploited in the wild
- 0
About Dromara
dromara is an open-source community focused on providing high-quality Java-based middleware and frameworks.
Dromara technologies
Latest Dromara vulnerabilities
- CVE-2026-92993: Dromara mayfly-go OS command injection in machine scriptmediumCVSS 6.3EPSS 1.5%
- CVE-2026-92992: Dromara mayfly-go missing authorization in AI AssistantmediumCVSS 6.3EPSS 0.4%
- CVE-2026-88616: RuoYi-Vue-Plus authorization bypass in workflow task completionhighCVSS 8.8EPSS 0.7%
- CVE-2026-91996: lamp-cloud authentication bypass via anno path whitelisthighCVSS 7.5EPSS 0.5%
- CVE-2026-91993: Jpom workspace isolation bypass in repository enumerationmediumCVSS 4.3EPSS 0.3%
- CVE-2026-90510: dromara orion-visor hardcoded cryptographic key in host key encryptionhighCVSS 8.3EPSS 0.5%
- CVE-2026-90509: dromara orion-visor hardcoded credential authentication bypasshighCVSS 7.3EPSS 0.5%
- CVE-2026-71807: RuoYi-Cloud-Plus workflow task authorization bypass in FlwTaskControllermediumCVSS 4.3EPSS 0.4%
- CVE-2026-78140: Dromara UJCMS Server-Side Template Injection in WebFileTemplateControllermediumCVSS 4.7EPSS 0.4%
- CVE-2026-77795: Dromara RuoYi-Vue-Plus improper authorization in workflow controllersmediumCVSS 6.3EPSS 0.4%
- CVE-2026-19758: dromara lamp-cloud path traversal in chunk-check endpointhighCVSS 7.3EPSS 0.6%
- CVE-2026-19757: Dromara lamp-cloud path traversal in file uploadhighCVSS 7.3EPSS 0.6%
- CVE-2026-19756: Dromara lamp-cloud path traversal in code generatormediumCVSS 6.3EPSS 0.4%
- CVE-2026-69102: Dromara MaxKey hard-coded JWT secret authentication bypasscriticalCVSS 9.8EPSS 0.6%
- CVE-2026-69100: LAMP Rapid Development Platform remote code execution in GlueFactoryhighCVSS 8.8EPSS 1.0%
- CVE-2026-67345: MaxKey insufficient redirect URI validation in DefaultRedirectResolverhighCVSS 8.1
- CVE-2026-58176: dromara RuoYi-Vue-Plus missing authorization in FlwTaskControllermediumCVSS 6.5
- CVE-2026-9498: Dromara lamp-cloud RCE in Message Template HandlermediumCVSS 6.3EPSS 0.0%
- CVE-2026-6125: Dromara warm-flow SpEL injection in Workflow Definition HandlermediumCVSS 6.3
- CVE-2026-5529: Dromara lamp-cloud improper authorization in DefUserControllermediumCVSS 4.3EPSS 0.3%
Most severe Dromara vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-69102: Dromara MaxKey hard-coded JWT secret authentication bypasscriticalCVSS 9.8EPSS 0.6%
- CVE-2026-69100: LAMP Rapid Development Platform remote code execution in GlueFactoryhighCVSS 8.8EPSS 1.0%
- CVE-2026-88616: RuoYi-Vue-Plus authorization bypass in workflow task completionhighCVSS 8.8EPSS 0.7%
- CVE-2026-90510: dromara orion-visor hardcoded cryptographic key in host key encryptionhighCVSS 8.3EPSS 0.5%
- CVE-2026-67345: MaxKey insufficient redirect URI validation in DefaultRedirectResolverhighCVSS 8.1
- CVE-2026-91996: lamp-cloud authentication bypass via anno path whitelisthighCVSS 7.5EPSS 0.5%
- CVE-2026-19758: dromara lamp-cloud path traversal in chunk-check endpointhighCVSS 7.3EPSS 0.6%
- CVE-2026-19757: Dromara lamp-cloud path traversal in file uploadhighCVSS 7.3EPSS 0.6%
- CVE-2026-90509: dromara orion-visor hardcoded credential authentication bypasshighCVSS 7.3EPSS 0.5%
- CVE-2026-58176: dromara RuoYi-Vue-Plus missing authorization in FlwTaskControllermediumCVSS 6.5
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 1 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 1 | 0 | |
| 3 Aug 2026 | 1 | 0 | |
| 10 Aug 2026 | 4 | 1 | |
| 17 Aug 2026 | 2 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 3 | 0 | |
| 14 Sep 2026 | 5 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/dromara.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Dromara vulnerabilities", https://junglewise.ai/threats/vendors/dromara, 26 September 2026.