CVE-2026-97323Medium· 6.3▾ TwilightPoC availableA vulnerability was determined in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. This impacts the function getOriginalFilename of the file yudao-module-mp/src/main/java/cn/iocoder/yudao/module/mp/service/material/MpMaterialServiceImpl…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 34.7 · likelihood 0 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
A vulnerability was determined in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. This impacts the function getOriginalFilename of the file yudao-module-mp/src/main/java/cn/iocoder/yudao/module/mp/service/material/MpMaterialServiceImpl.java of the component File Upload. Executing a manipulation can lead to path traversal. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-97321Medium· 6.3A vulnerability has been found in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08
CVE-2026-97324High· 7.3A vulnerability was identified in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08
CVE-2026-97325Medium· 4.3A security flaw has been discovered in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08
CVE-2026-97322Medium· 4.3A vulnerability was found in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08
CVE-2026-97320Medium· 6.3A flaw has been found in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08
CVE-2010-2861Critical· 9.8Multiple directory traversal vulnerabilities in the administrator console in Adobe ColdFusion 9.0.1 and earlier allow remote attackers to read arbitrary files via the locale parameter to (1) CFIDE/administrator/settings/mappings.cfm, (2)…