dromara lamp-cloud
6 known vulnerabilities in dromara lamp-cloud, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-94536 CVSS 5.3 medium lamp-cloud through 5.10.0 fails to validate the employeeId parameter in the /anyone/visible/resource endpoint, allowing authenticated…
- CVE-2026-94535 CVSS 7.1 high lamp-cloud through 5.10.0 contains an authorization bypass vulnerability in the deleteMyNotice endpoint that allows authenticated users to…
- CVE-2026-94534 CVSS 7.1 high lamp-cloud through 5.10.0 fails to validate user identity in PUT /anyone/baseInfo and PUT /anyone/avatar endpoints, allowing authenticated…
- CVE-2026-94533 CVSS 7.1 high lamp-cloud through 5.10.0 contains an authorization bypass vulnerability in FileAnyoneController that allows authenticated users to…
- CVE-2026-94532 CVSS 7.1 high lamp-cloud through 5.10.0 contains an authorization bypass vulnerability in the getUserInfoById endpoint that allows authenticated users…
- CVE-2026-91996 CVSS 8.7 high lamp-cloud through 5.10.0 whitelists the path pattern /*/anno/** for anonymous access, allowing unauthenticated attackers to read the…