{"schema_version":1,"title":"Dromara vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 25 vulnerabilities in Dromara: 5 in the last 7 days and 22 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2026-94536, was published on 21 September 2026. 2 technologies have a page of their own.","url":"https://junglewise.ai/threats/vendors/dromara","json_url":"https://junglewise.ai/threats/vendors/dromara.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/dromara","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":9,"all_time":25,"critical":1,"exploited":0,"last_7_days":5,"last_30_days":13,"last_90_days":22,"last_365_days":25},"latest":[{"cve":"CVE-2026-94536","cvss":4.3,"epss":0.0034,"slug":"cve-2026-94536-lamp-cloud-through-5-10-0-fails-to-validate-the-employeeid","title":"lamp-cloud broken object level authorization in /anyone/visible/resource","severity":"medium","exploited":false,"published_at":"2026-09-21T22:17:00.64+00:00","url":"https://junglewise.ai/threats/cve-2026-94536-lamp-cloud-through-5-10-0-fails-to-validate-the-employeeid"},{"cve":"CVE-2026-94535","cvss":7.1,"epss":0.0047,"slug":"cve-2026-94535-lamp-cloud-through-5-10-0-contains-an-authorization-bypass","title":"lamp-cloud authorization bypass in deleteMyNotice","severity":"high","exploited":false,"published_at":"2026-09-21T22:17:00.487+00:00","url":"https://junglewise.ai/threats/cve-2026-94535-lamp-cloud-through-5-10-0-contains-an-authorization-bypass"},{"cve":"CVE-2026-94533","cvss":6.5,"epss":0.0044,"slug":"cve-2026-94533-lamp-cloud-through-5-10-0-contains-an-authorization-bypass","title":"lamp-cloud authorization bypass in FileAnyoneController","severity":"medium","exploited":false,"published_at":"2026-09-21T22:17:00.173+00:00","url":"https://junglewise.ai/threats/cve-2026-94533-lamp-cloud-through-5-10-0-contains-an-authorization-bypass"},{"cve":"CVE-2026-94532","cvss":6.5,"epss":0.0044,"slug":"cve-2026-94532-lamp-cloud-through-5-10-0-contains-an-authorization-bypass","title":"lamp-cloud authorization bypass in getUserInfoById endpoint","severity":"medium","exploited":false,"published_at":"2026-09-21T22:17:00.01+00:00","url":"https://junglewise.ai/threats/cve-2026-94532-lamp-cloud-through-5-10-0-contains-an-authorization-bypass"},{"cve":"CVE-2026-93961","cvss":5.3,"epss":0.0058,"slug":"cve-2026-93961-a-security-flaw-has-been-discovered-in-dromara-ujcms-up-to-12-3-1","title":"Dromara UJCMS improper authorization in UserController username enumeration","severity":"medium","exploited":false,"published_at":"2026-09-20T05:16:28.093+00:00","url":"https://junglewise.ai/threats/cve-2026-93961-a-security-flaw-has-been-discovered-in-dromara-ujcms-up-to-12-3-1"},{"cve":"CVE-2026-92993","cvss":6.3,"epss":0.0146,"slug":"cve-2026-92993-dromara-mayfly-go-os-command-injection-in-machine-script","title":"Dromara mayfly-go OS command injection in machine script","severity":"medium","exploited":false,"published_at":"2026-09-17T20:19:00.233+00:00","url":"https://junglewise.ai/threats/cve-2026-92993-dromara-mayfly-go-os-command-injection-in-machine-script"},{"cve":"CVE-2026-92992","cvss":6.3,"epss":0.0039,"slug":"cve-2026-92992-dromara-mayfly-go-missing-authorization-in-ai-assistant","title":"Dromara mayfly-go missing authorization in AI Assistant","severity":"medium","exploited":false,"published_at":"2026-09-17T19:17:07.43+00:00","url":"https://junglewise.ai/threats/cve-2026-92992-dromara-mayfly-go-missing-authorization-in-ai-assistant"},{"cve":"CVE-2026-88616","cvss":8.8,"epss":0.0069,"slug":"cve-2026-88616-ruoyi-vue-plus-authorization-bypass-in-workflow-task-completion","title":"RuoYi-Vue-Plus authorization bypass in workflow task completion","severity":"high","exploited":false,"published_at":"2026-09-15T15:17:24.887+00:00","url":"https://junglewise.ai/threats/cve-2026-88616-ruoyi-vue-plus-authorization-bypass-in-workflow-task-completion"},{"cve":"CVE-2026-91996","cvss":7.5,"epss":0.005,"slug":"cve-2026-91996-lamp-cloud-authentication-bypass-via-anno-path-whitelist","title":"lamp-cloud authentication bypass via anno path whitelist","severity":"high","exploited":false,"published_at":"2026-09-15T12:17:55.093+00:00","url":"https://junglewise.ai/threats/cve-2026-91996-lamp-cloud-authentication-bypass-via-anno-path-whitelist"},{"cve":"CVE-2026-91993","cvss":4.3,"epss":0.0034,"slug":"cve-2026-91993-jpom-workspace-isolation-bypass-in-repository-enumeration","title":"Jpom workspace isolation bypass in repository enumeration","severity":"medium","exploited":false,"published_at":"2026-09-15T12:17:54.64+00:00","url":"https://junglewise.ai/threats/cve-2026-91993-jpom-workspace-isolation-bypass-in-repository-enumeration"},{"cve":"CVE-2026-90510","cvss":8.3,"epss":0.005,"slug":"cve-2026-90510-dromara-orion-visor-hardcoded-cryptographic-key-in-host-key","title":"dromara orion-visor hardcoded cryptographic key in host key encryption","severity":"high","exploited":false,"published_at":"2026-09-13T11:16:59.827+00:00","url":"https://junglewise.ai/threats/cve-2026-90510-dromara-orion-visor-hardcoded-cryptographic-key-in-host-key"},{"cve":"CVE-2026-90509","cvss":7.3,"epss":0.005,"slug":"cve-2026-90509-dromara-orion-visor-hardcoded-credential-authentication-bypass","title":"dromara orion-visor hardcoded credential authentication bypass","severity":"high","exploited":false,"published_at":"2026-09-13T10:16:56.117+00:00","url":"https://junglewise.ai/threats/cve-2026-90509-dromara-orion-visor-hardcoded-credential-authentication-bypass"},{"cve":"CVE-2026-71807","cvss":4.3,"epss":0.0042,"slug":"cve-2026-71807-ruoyi-cloud-plus-workflow-task-authorization-bypass-in","title":"RuoYi-Cloud-Plus workflow task authorization bypass in FlwTaskController","severity":"medium","exploited":false,"published_at":"2026-09-09T22:18:19.173+00:00","url":"https://junglewise.ai/threats/cve-2026-71807-ruoyi-cloud-plus-workflow-task-authorization-bypass-in"},{"cve":"CVE-2026-78140","cvss":4.7,"epss":0.0041,"slug":"cve-2026-78140-dromara-ujcms-server-side-template-injection-in","title":"Dromara UJCMS Server-Side Template Injection in WebFileTemplateController","severity":"medium","exploited":false,"published_at":"2026-08-23T20:16:50.38+00:00","url":"https://junglewise.ai/threats/cve-2026-78140-dromara-ujcms-server-side-template-injection-in"},{"cve":"CVE-2026-77795","cvss":6.3,"epss":0.0035,"slug":"cve-2026-77795-dromara-ruoyi-vue-plus-improper-authorization-in-workflow","title":"Dromara RuoYi-Vue-Plus improper authorization in workflow controllers","severity":"medium","exploited":false,"published_at":"2026-08-21T19:17:51.393+00:00","url":"https://junglewise.ai/threats/cve-2026-77795-dromara-ruoyi-vue-plus-improper-authorization-in-workflow"},{"cve":"CVE-2026-19758","cvss":7.3,"epss":0.0062,"slug":"cve-2026-19758-dromara-lamp-cloud-path-traversal-in-chunk-check-endpoint","title":"dromara lamp-cloud path traversal in chunk-check endpoint","severity":"high","exploited":false,"published_at":"2026-08-14T01:18:56.68+00:00","url":"https://junglewise.ai/threats/cve-2026-19758-dromara-lamp-cloud-path-traversal-in-chunk-check-endpoint"},{"cve":"CVE-2026-19757","cvss":7.3,"epss":0.0062,"slug":"cve-2026-19757-dromara-lamp-cloud-path-traversal-in-file-upload","title":"Dromara lamp-cloud path traversal in file upload","severity":"high","exploited":false,"published_at":"2026-08-14T01:18:53.793+00:00","url":"https://junglewise.ai/threats/cve-2026-19757-dromara-lamp-cloud-path-traversal-in-file-upload"},{"cve":"CVE-2026-19756","cvss":6.3,"epss":0.0043,"slug":"cve-2026-19756-dromara-lamp-cloud-path-traversal-in-code-generator","title":"Dromara lamp-cloud path traversal in code generator","severity":"medium","exploited":false,"published_at":"2026-08-13T23:17:14.617+00:00","url":"https://junglewise.ai/threats/cve-2026-19756-dromara-lamp-cloud-path-traversal-in-code-generator"},{"cve":"CVE-2026-69102","cvss":9.8,"epss":0.0064,"slug":"cve-2026-69102-dromara-maxkey-hard-coded-jwt-secret-authentication-bypass","title":"Dromara MaxKey hard-coded JWT secret authentication bypass","severity":"critical","exploited":false,"published_at":"2026-08-11T18:18:17.587+00:00","url":"https://junglewise.ai/threats/cve-2026-69102-dromara-maxkey-hard-coded-jwt-secret-authentication-bypass"},{"cve":"CVE-2026-69100","cvss":8.8,"epss":0.0102,"slug":"cve-2026-69100-lamp-rapid-development-platform-remote-code-execution-in","title":"LAMP Rapid Development Platform remote code execution in GlueFactory","severity":"high","exploited":false,"published_at":"2026-08-04T16:16:28.34+00:00","url":"https://junglewise.ai/threats/cve-2026-69100-lamp-rapid-development-platform-remote-code-execution-in"},{"cve":"CVE-2026-67345","cvss":8.1,"slug":"cve-2026-67345-maxkey-insufficient-redirect-uri-validation-in","title":"MaxKey insufficient redirect URI validation in DefaultRedirectResolver","severity":"high","exploited":false,"published_at":"2026-07-30T15:16:35.583+00:00","url":"https://junglewise.ai/threats/cve-2026-67345-maxkey-insufficient-redirect-uri-validation-in"},{"cve":"CVE-2026-58176","cvss":6.5,"slug":"cve-2026-58176-dromara-ruoyi-vue-plus-missing-authorization-in-flwtaskcontroller","title":"dromara RuoYi-Vue-Plus missing authorization in FlwTaskController","severity":"medium","exploited":false,"published_at":"2026-06-30T17:16:24.72+00:00","url":"https://junglewise.ai/threats/cve-2026-58176-dromara-ruoyi-vue-plus-missing-authorization-in-flwtaskcontroller"},{"cve":"CVE-2026-9498","cvss":6.3,"epss":0.0004,"slug":"cve-2026-9498-dromara-lamp-cloud-rce-in-message-template-handler","title":"Dromara lamp-cloud RCE in Message Template Handler","severity":"medium","exploited":false,"published_at":"2026-05-25T20:16:38.29+00:00","url":"https://junglewise.ai/threats/cve-2026-9498-dromara-lamp-cloud-rce-in-message-template-handler"},{"cve":"CVE-2026-6125","cvss":6.3,"slug":"cve-2026-6125-dromara-warm-flow-spel-injection-in-workflow-definition-handler","title":"Dromara warm-flow SpEL injection in Workflow Definition Handler","severity":"medium","exploited":false,"published_at":"2026-04-12T10:16:01.277+00:00","url":"https://junglewise.ai/threats/cve-2026-6125-dromara-warm-flow-spel-injection-in-workflow-definition-handler"},{"cve":"CVE-2026-5529","cvss":4.3,"epss":0.0027,"slug":"cve-2026-5529-dromara-lamp-cloud-improper-authorization-in-defusercontroller","title":"Dromara lamp-cloud improper authorization in DefUserController","severity":"medium","exploited":false,"published_at":"2026-04-05T01:16:47.45+00:00","url":"https://junglewise.ai/threats/cve-2026-5529-dromara-lamp-cloud-improper-authorization-in-defusercontroller"}],"vendor":{"hub":true,"name":"Dromara","slug":"dromara","homepage":"https://dromara.org/","description":"dromara is an open-source community focused on providing high-quality Java-based middleware and frameworks.","url":"https://junglewise.ai/threats/vendors/dromara"},"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-10","critical":1,"exploited":0,"vulnerabilities":4},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":3},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":6},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":4}],"most_severe":[{"cve":"CVE-2026-69102","cvss":9.8,"epss":0.0064,"slug":"cve-2026-69102-dromara-maxkey-hard-coded-jwt-secret-authentication-bypass","title":"Dromara MaxKey hard-coded JWT secret authentication bypass","severity":"critical","exploited":false,"published_at":"2026-08-11T18:18:17.587+00:00","url":"https://junglewise.ai/threats/cve-2026-69102-dromara-maxkey-hard-coded-jwt-secret-authentication-bypass"},{"cve":"CVE-2026-69100","cvss":8.8,"epss":0.0102,"slug":"cve-2026-69100-lamp-rapid-development-platform-remote-code-execution-in","title":"LAMP Rapid Development Platform remote code execution in GlueFactory","severity":"high","exploited":false,"published_at":"2026-08-04T16:16:28.34+00:00","url":"https://junglewise.ai/threats/cve-2026-69100-lamp-rapid-development-platform-remote-code-execution-in"},{"cve":"CVE-2026-88616","cvss":8.8,"epss":0.0069,"slug":"cve-2026-88616-ruoyi-vue-plus-authorization-bypass-in-workflow-task-completion","title":"RuoYi-Vue-Plus authorization bypass in workflow task completion","severity":"high","exploited":false,"published_at":"2026-09-15T15:17:24.887+00:00","url":"https://junglewise.ai/threats/cve-2026-88616-ruoyi-vue-plus-authorization-bypass-in-workflow-task-completion"},{"cve":"CVE-2026-90510","cvss":8.3,"epss":0.005,"slug":"cve-2026-90510-dromara-orion-visor-hardcoded-cryptographic-key-in-host-key","title":"dromara orion-visor hardcoded cryptographic key in host key encryption","severity":"high","exploited":false,"published_at":"2026-09-13T11:16:59.827+00:00","url":"https://junglewise.ai/threats/cve-2026-90510-dromara-orion-visor-hardcoded-cryptographic-key-in-host-key"},{"cve":"CVE-2026-67345","cvss":8.1,"slug":"cve-2026-67345-maxkey-insufficient-redirect-uri-validation-in","title":"MaxKey insufficient redirect URI validation in DefaultRedirectResolver","severity":"high","exploited":false,"published_at":"2026-07-30T15:16:35.583+00:00","url":"https://junglewise.ai/threats/cve-2026-67345-maxkey-insufficient-redirect-uri-validation-in"},{"cve":"CVE-2026-91996","cvss":7.5,"epss":0.005,"slug":"cve-2026-91996-lamp-cloud-authentication-bypass-via-anno-path-whitelist","title":"lamp-cloud authentication bypass via anno path whitelist","severity":"high","exploited":false,"published_at":"2026-09-15T12:17:55.093+00:00","url":"https://junglewise.ai/threats/cve-2026-91996-lamp-cloud-authentication-bypass-via-anno-path-whitelist"},{"cve":"CVE-2026-19758","cvss":7.3,"epss":0.0062,"slug":"cve-2026-19758-dromara-lamp-cloud-path-traversal-in-chunk-check-endpoint","title":"dromara lamp-cloud path traversal in chunk-check endpoint","severity":"high","exploited":false,"published_at":"2026-08-14T01:18:56.68+00:00","url":"https://junglewise.ai/threats/cve-2026-19758-dromara-lamp-cloud-path-traversal-in-chunk-check-endpoint"},{"cve":"CVE-2026-19757","cvss":7.3,"epss":0.0062,"slug":"cve-2026-19757-dromara-lamp-cloud-path-traversal-in-file-upload","title":"Dromara lamp-cloud path traversal in file upload","severity":"high","exploited":false,"published_at":"2026-08-14T01:18:53.793+00:00","url":"https://junglewise.ai/threats/cve-2026-19757-dromara-lamp-cloud-path-traversal-in-file-upload"},{"cve":"CVE-2026-90509","cvss":7.3,"epss":0.005,"slug":"cve-2026-90509-dromara-orion-visor-hardcoded-credential-authentication-bypass","title":"dromara orion-visor hardcoded credential authentication bypass","severity":"high","exploited":false,"published_at":"2026-09-13T10:16:56.117+00:00","url":"https://junglewise.ai/threats/cve-2026-90509-dromara-orion-visor-hardcoded-credential-authentication-bypass"},{"cve":"CVE-2026-94535","cvss":7.1,"epss":0.0047,"slug":"cve-2026-94535-lamp-cloud-through-5-10-0-contains-an-authorization-bypass","title":"lamp-cloud authorization bypass in deleteMyNotice","severity":"high","exploited":false,"published_at":"2026-09-21T22:17:00.487+00:00","url":"https://junglewise.ai/threats/cve-2026-94535-lamp-cloud-through-5-10-0-contains-an-authorization-bypass"}],"generated_at":"2026-09-26T12:07:00.15149+00:00","technologies":[{"name":"Dromara Lamp-Cloud","slug":"lamp-cloud","vulnerabilities":6,"url":"https://junglewise.ai/threats/technologies/lamp-cloud"},{"name":"Dromara RuoYi-Vue-Plus","slug":"ruoyi-vue-plus","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/ruoyi-vue-plus"}]}