Vulnerabilities
8 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-8211 | A vulnerability was found in Roothub up to 2.6. A vulnerability was found in Roothub up to 2.6. It has been declared as problematic. Affected by this vulnerability is the function Edit of the file src/main/java/cn/roothub/web/admin/SystemConfigAdminController.java. The manipulation leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. NVD description · AI analysis pending | 2.0 | <1% | PoC |
| — | |
| CVE-2024-33120 | Roothub v2.5 was discovered to contain an arbitrary file upload vulnerability via the customPath parameter in the upload() function. Roothub v2.5 was discovered to contain an arbitrary file upload vulnerability via the customPath parameter in the upload() function. This vulnerability allows attackers to execute arbitrary code via a crafted JSP file. NVD description · AI analysis pending | 9.8 group max | <1% |
| — | ||
| CVE-2024-33121 | Roothub v2.6 was discovered to contain a SQL injection vulnerability via the 's' parameter in the search() function. Roothub v2.6 was discovered to contain a SQL injection vulnerability via the 's' parameter in the search() function. NVD description · AI analysis pending | 6.3 | <1% |
| — | ||
| CVE-2022-28052 | Directory Traversal vulnerability in file cn/roothub/store/FileSystemStorageService in function store in Roothub 2.6.0 allows remote attackers with low privlege Directory Traversal vulnerability in file cn/roothub/store/FileSystemStorageService in function store in Roothub 2.6.0 allows remote attackers with low privlege to arbitrarily upload files via /common/upload API, which could lead to remote arbitrary code execution. NVD description · AI analysis pending | 8.0 | 3% | PoC |
| — | |
| CVE-2022-27473 +1 in the same advisory: …27472 | SQL injection vulnerability in Topics Searching feature of Roothub 2.6.0 allows unauthorized attackers to execute arbitrary SQL commands via the "s" parameter r SQL injection vulnerability in Topics Searching feature of Roothub 2.6.0 allows unauthorized attackers to execute arbitrary SQL commands via the "s" parameter remotely. NVD description · AI analysis pending | 9.8 | 1% | PoC |
| — |