r1bbit CVE Vulnerabilities & CVE List (10)

Products (CPE): — CVEs: 10

r1bbit vulnerability overview

Aggregates CVE and security vulnerability intelligence across all r1bbit-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Historical issues mainly involve vendor risk sql injection, vendor risk xxe, and vendor risk path handling and related problems; some flaws may lead to vendor impact data exposure and vendor impact file overwrite.

Vulnerability distribution trend (last 24 months)

Showing 110 of 10 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2025-25586 yimioa before v2024.07.04 was discovered to contain an information disclosure vulnerability via the component /resources/application.yml. [email protected] 4.2 0.10% 2025-03-18 2026-06-17
CVE-2025-25582 yimioa before v2024.07.04 was discovered to contain a SQL injection vulnerability via the selectNoticeList() method at /xml/OaNoticeMapper.xml. [email protected] 6.1 0.16% 2025-03-18 2026-06-17
CVE-2025-25590 yimioa before v2024.07.04 was discovered to contain a SQL injection vulnerability via the component /mapper/xml/AddressDao.xml. [email protected] 6.1 0.17% 2025-03-18 2026-06-17
CVE-2025-25585 Incorrect access control in the component /config/WebSecurityConfig.java of yimioa before v2024.07.04 allows unauthorized attackers to arbitrarily modify Administrator passwords. [email protected] 7.3 0.26% 2025-03-18 2026-06-17
CVE-2025-25580 yimioa before v2024.07.04 was discovered to contain a SQL injection vulnerability via the listNameBySql() method at /xml/UserMapper.xml. [email protected] 6.1 0.17% 2025-03-18 2026-06-17
CVE-2025-1227 A vulnerability was found in ywoa up to 2024.07.03. It has been rated as critical. This issue affects the function selectList of the file com/cloudweb/oa/mapper/xml/AddressDao.xml. The manipulation leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 2024.07.04 is able to address this issue. It is recommended to upgrade the affected component. [email protected] 5.3 0.47% 2025-02-12 2026-06-17
CVE-2025-1226 A vulnerability was found in ywoa up to 2024.07.03. It has been declared as critical. This vulnerability affects unknown code of the file /oa/setup/setup.jsp. The manipulation leads to improper authorization. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 2024.07.04 is able to address this issue. It is recommended to upgrade the affected component. [email protected] 6.9 0.77% 2025-02-12 2026-06-17
CVE-2025-1225 A vulnerability, which was classified as problematic, has been found in ywoa up to 2024.07.03. This issue affects the function extract of the file c-main/src/main/java/com/redmoon/weixin/aes/XMLParse.java of the component WXCallBack Interface. The manipulation leads to xml external entity reference. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 2024.07.04 is able to address this issue. It is recommended to upgrade the aff [email protected] 5.3 0.35% 2025-02-12 2026-06-17
CVE-2025-1224 A vulnerability classified as critical was found in ywoa up to 2024.07.03. This vulnerability affects the function listNameBySql of the file com/cloudweb/oa/mapper/xml/UserMapper.xml. The manipulation leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 2024.07.04 is able to address this issue. It is recommended to upgrade the affected component. [email protected] 5.3 0.38% 2025-02-12 2026-06-17
CVE-2025-1216 A vulnerability, which was classified as critical, has been found in ywoa up to 2024.07.03. This issue affects the function selectNoticeList of the file com/cloudweb/oa/mapper/xml/OaNoticeMapper.xml. The manipulation of the argument sort leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 2024.07.04 is able to address this issue. It is recommended to upgrade the affected component. [email protected] 5.3 0.48% 2025-02-12 2026-06-17
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence