---
id: CVE-2026-97321
title: >-
  A vulnerability has been found in YunaiV/zhijiantianya ruoyi-vue-pro up to
  2026.08
summary: >-
  A vulnerability has been found in YunaiV/zhijiantianya ruoyi-vue-pro up to
  2026.08. The impacted element is the function
  GoViewDataServiceImpl.getDataBySQL of the file
  yudao-module-report/src/main/java/cn/iocoder/yudao/module/report/serv…
severity: medium
cvss: 6.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-74
  - CWE-89
vendor: YunaiV
product: ruoyi-vue-pro
affected:
  - ruoyi-vue-pro 2026.08
  - ruoyi-vue-pro 2026.08
published: '2026-09-24'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T21:08:55.030'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-97321'
references:
  - url: 'https://vuldb.com/cve/CVE-2026-97321'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/908272'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/409329'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/409329/cti'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/908272'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-24T18:50:44.044955Z'
ingestedAt: '2026-09-24T18:49:36.719Z'
epss: 0.00233
epssPercentile: 0.12727
---

## Overview

A vulnerability has been found in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. The impacted element is the function GoViewDataServiceImpl.getDataBySQL of the file yudao-module-report/src/main/java/cn/iocoder/yudao/module/report/service/goview/GoViewDataServiceImpl.java of the component GoView Data Endpoint. Such manipulation of the argument sql leads to sql injection. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
