Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://github.com/jjcjgo/CVE-2026-38812-RuoYi-SQL-Injection |
|
Fri, 19 Jun 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ruoyi
Ruoyi ruoyi |
|
| Vendors & Products |
Ruoyi
Ruoyi ruoyi |
Thu, 18 Jun 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | SQL Injection in RuoYi Code Generation Endpoint |
Wed, 17 Jun 2026 05:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | SQL Injection in RuoYi Code Generation Endpoint |
Tue, 16 Jun 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-89 | |
| Metrics |
cvssV3_1
|
Mon, 15 Jun 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | RuoYi v4.8.2 is vulnerable to SQL Injection via the /tool/gen/createTable endpoint. The issue affects the code generation module and may allow an authenticated attacker with administrative privileges to access sensitive database information. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-06-16T13:51:09.133Z
Reserved: 2026-04-06T00:00:00.000Z
Link: CVE-2026-38812
Updated: 2026-06-16T13:50:56.313Z
Status : Deferred
Published: 2026-06-15T20:16:27.103
Modified: 2026-06-16T15:50:58.757
Link: CVE-2026-38812
No data.
OpenCVE Enrichment
Updated: 2026-06-19T09:36:02Z