VulnSea

dromara has 12 CVEs on record. Disclosure cadence is accelerating: 12 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 12. The median CVSS is 6.5 (medium). None have a confirmed exploitation report. The most common weakness class is CWE-639 (6). Most affected products: lamp-cloud (6), mayfly-go (2), orion-visor (2).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
6.5
Publish → KEV
Last 90 days
12 prev 0

Products

  • lamp-cloud 6
  • mayfly-go 2
  • orion-visor 2
  • Jpom 1
  • UJCMS 1
12
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

dromara vulnerabilities

CVEs affecting dromara, newest first. Open any entry for full detail, references, and exploit status.

12 CVEsRSS

CVE-2026-94536Medium· 4.3
yesterday

lamp-cloud through 5.10.0 fails to validate the employeeId parameter in the /anyone/visible/resource endpoint, allowing authenticated users to read any employee's roles and permissions

lamp-cloud through 5.10.0 fails to validate the employeeId parameter in the /anyone/visible/resource endpoint, allowing authenticated users to read any employee's roles and permissions. Attackers can supply arbitrary employeeId values to…

Sunlitdromara · lamp-cloudvia NVD
CVE-2026-94532Medium· 6.5
yesterday

lamp-cloud through 5.10.0 contains an authorization bypass vulnerability in the getUserInfoById endpoint that allows authenticated users to read any other user's full profile

lamp-cloud through 5.10.0 contains an authorization bypass vulnerability in the getUserInfoById endpoint that allows authenticated users to read any other user's full profile. Attackers can iterate the userId parameter to harvest sensiti…

Sunlitdromara · lamp-cloudvia NVD
CVE-2026-94535High· 7.1
yesterday

lamp-cloud through 5.10.0 contains an authorization bypass vulnerability in the deleteMyNotice endpoint that allows authenticated users to delete other users' notifications

lamp-cloud through 5.10.0 contains an authorization bypass vulnerability in the deleteMyNotice endpoint that allows authenticated users to delete other users' notifications. Attackers can call the DELETE /anyone/extendNotice/deleteMyNoti…

Twilightdromara · lamp-cloudvia NVD
CVE-2026-94534High· 7.1
yesterday

lamp-cloud through 5.10.0 fails to validate user identity in PUT /anyone/baseInfo and PUT /anyone/avatar endpoints, allowing authenticated attackers to modify arbitrary user profiles

lamp-cloud through 5.10.0 fails to validate user identity in PUT /anyone/baseInfo and PUT /anyone/avatar endpoints, allowing authenticated attackers to modify arbitrary user profiles. Attackers can supply target user IDs in request bodie…

Twilightdromara · lamp-cloudvia NVD
CVE-2026-94533Medium· 6.5
yesterday

lamp-cloud through 5.10.0 contains an authorization bypass vulnerability in FileAnyoneController that allows authenticated users to download arbitrary attachments

lamp-cloud through 5.10.0 contains an authorization bypass vulnerability in FileAnyoneController that allows authenticated users to download arbitrary attachments. Attackers can retrieve other users' stored files by supplying valid attac…

Sunlitdromara · lamp-cloudvia NVD
CVE-2026-93961Medium· 5.3
2d ago

A security flaw has been discovered in Dromara UJCMS up to 12.3.1

A security flaw has been discovered in Dromara UJCMS up to 12.3.1. The affected element is the function usernameExist of the file ujcms-cms/src/main/java/com/ujcms/cms/core/web/api/UserController.java of the component UserController. Per…

SunlitDromara · UJCMSEPSS 0.42%via NVD
CVE-2026-92993Medium· 6.3
5d ago

A vulnerability was detected in Dromara mayfly-go up to 1.11.5

A vulnerability was detected in Dromara mayfly-go up to 1.11.5. The impacted element is the function RunMachineScript of the file server/internal/machine/api/machine_script.go of the component Machine Script Feature. The manipulation of …

SunlitDromara · mayfly-goEPSS 1.5%via NVD
CVE-2026-92992Medium· 6.3PoC
5d ago

A security vulnerability has been detected in Dromara mayfly-go up to 1.11.5

A security vulnerability has been detected in Dromara mayfly-go up to 1.11.5. The affected element is an unknown function of the file server/internal/ai/api/ai.go of the component AI Assistant. The manipulation leads to missing authoriza…

TwilightDromara · mayfly-goEPSS 0.28%via NVD
CVE-2026-91996High· 7.5PoC
1w ago

lamp-cloud through 5.10.0 whitelists the path pattern /*/anno/** for anonymous access, allowing unauthenticated attackers to read the server's full JVM system property map

lamp-cloud through 5.10.0 whitelists the path pattern /*/anno/** for anonymous access, allowing unauthenticated attackers to read the server's full JVM system property map. Attackers can send POST requests to /defGenProject/anno/getPrope…

Midnightdromara · lamp-cloudEPSS 0.36%via NVD
CVE-2026-91993Medium· 4.3PoC
1w ago

Jpom through 2.11.12 fails to validate workspace ownership when resolving repositoryId on the /build/branch-list endpoint, allowing authenticated users to access repositories from other workspaces

Jpom through 2.11.12 fails to validate workspace ownership when resolving repositoryId on the /build/branch-list endpoint, allowing authenticated users to access repositories from other workspaces. Attackers can submit repository identif…

Twilightdromara · JpomEPSS 0.25%via NVD
CVE-2026-90509High· 7.3PoC
1w ago

A weakness has been identified in dromara orion-visor up to 2.5.7

A weakness has been identified in dromara orion-visor up to 2.5.7. Affected by this issue is the function ExposeApiAspect.beforeExposeApi of the file ExposeApiAspect.java. Executing a manipulation can lead to hard-coded credentials. The …

Midnightdromara · orion-visorEPSS 0.29%via NVD
CVE-2026-90510High· 8.3PoC
1w ago

A security vulnerability has been detected in dromara orion-visor up to 2.5.7

A security vulnerability has been detected in dromara orion-visor up to 2.5.7. This affects the function HostKeyServiceImpl.encryptKey of the file orion-visor-modules/orion-visor-module-asset/orion-visor-module-asset-service/src/main/jav…

Midnightdromara · orion-visorEPSS 0.29%via NVD
dromara vulnerabilities (CVEs) · VulnSea