VulnSea

Dromara has 7 CVEs on record. Disclosure cadence is accelerating: 7 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 7. The median CVSS is 6.3 (medium). None have a confirmed exploitation report. Most affected products: mayfly-go (2), orion-visor (2), Jpom (1).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
6.3
Publish → KEV
Last 90 days
7 prev 0

Products

  • mayfly-go 2
  • orion-visor 2
  • Jpom 1
  • UJCMS 1
  • lamp-cloud 1
7
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

Dromara vulnerabilities

CVEs affecting Dromara, newest first. Open any entry for full detail, references, and exploit status.

7 CVEsRSS

CVE-2026-93961Medium· 5.3
yesterday

A security flaw has been discovered in Dromara UJCMS up to 12.3.1

A security flaw has been discovered in Dromara UJCMS up to 12.3.1. The affected element is the function usernameExist of the file ujcms-cms/src/main/java/com/ujcms/cms/core/web/api/UserController.java of the component UserController. Per…

SunlitDromara · UJCMSEPSS 0.42%via NVD
CVE-2026-92993Medium· 6.3
4d ago

A vulnerability was detected in Dromara mayfly-go up to 1.11.5

A vulnerability was detected in Dromara mayfly-go up to 1.11.5. The impacted element is the function RunMachineScript of the file server/internal/machine/api/machine_script.go of the component Machine Script Feature. The manipulation of …

SunlitDromara · mayfly-goEPSS 1.5%via NVD
CVE-2026-92992Medium· 6.3PoC
4d ago

A security vulnerability has been detected in Dromara mayfly-go up to 1.11.5

A security vulnerability has been detected in Dromara mayfly-go up to 1.11.5. The affected element is an unknown function of the file server/internal/ai/api/ai.go of the component AI Assistant. The manipulation leads to missing authoriza…

TwilightDromara · mayfly-goEPSS 0.28%via NVD
CVE-2026-91996High· 7.5PoC
6d ago

lamp-cloud through 5.10.0 whitelists the path pattern /*/anno/** for anonymous access, allowing unauthenticated attackers to read the server's full JVM system property map

lamp-cloud through 5.10.0 whitelists the path pattern /*/anno/** for anonymous access, allowing unauthenticated attackers to read the server's full JVM system property map. Attackers can send POST requests to /defGenProject/anno/getPrope…

Midnightdromara · lamp-cloudEPSS 0.36%via NVD
CVE-2026-91993Medium· 4.3PoC
6d ago

Jpom through 2.11.12 fails to validate workspace ownership when resolving repositoryId on the /build/branch-list endpoint, allowing authenticated users to access repositories from other workspaces

Jpom through 2.11.12 fails to validate workspace ownership when resolving repositoryId on the /build/branch-list endpoint, allowing authenticated users to access repositories from other workspaces. Attackers can submit repository identif…

Twilightdromara · JpomEPSS 0.25%via NVD
CVE-2026-90509High· 7.3PoC
1w ago

A weakness has been identified in dromara orion-visor up to 2.5.7

A weakness has been identified in dromara orion-visor up to 2.5.7. Affected by this issue is the function ExposeApiAspect.beforeExposeApi of the file ExposeApiAspect.java. Executing a manipulation can lead to hard-coded credentials. The …

Midnightdromara · orion-visorEPSS 0.29%via NVD
CVE-2026-90510High· 8.3PoC
1w ago

A security vulnerability has been detected in dromara orion-visor up to 2.5.7

A security vulnerability has been detected in dromara orion-visor up to 2.5.7. This affects the function HostKeyServiceImpl.encryptKey of the file orion-visor-modules/orion-visor-module-asset/orion-visor-module-asset-service/src/main/jav…

Midnightdromara · orion-visorEPSS 0.29%via NVD
Dromara vulnerabilities (CVEs) · VulnSea