These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-93961 is a medium-severity vulnerability in Dromara UJCMS up to 12.3.1, affecting the UserController component. The issue is related to improper authorization in the usernameExist function. While the project was informed, it has not yet responded. The CVE record was published on 2026-09-20T05:16:28.093Z and has not been modified since then.
A vulnerability was detected in Dromara mayfly-go up to 1.11.5. The impacted element is the function RunMachineScript of the file server/internal/machine/api/machine_script.go of the component Machine Script Feature. The manipulation of the argument params results in os command injection. The attack can be executed remotely. The exploit is now public and may be used. Exploitation needs no admin account. A [truncated]
A high-severity vulnerability exists in RuoYi-Vue-Plus 6.0.0, allowing remote attackers to execute arbitrary code via specific components. Defenders should assess exposure, prioritize remediation, and verify affected versions. The vulnerability is caused by a flaw in the FlwTaskController.java component and related components. This issue requires immediate attention to prevent potential exploitation. Defe [truncated]
CVE-2026-91996 is a high-severity vulnerability in lamp-cloud that allows unauthenticated access to JVM system properties. This could expose sensitive information, including JVM classpath, filesystem paths, operating system details, and startup secrets. Defenders should prioritize verifying exposure and assessing impact. The vulnerability exists in lamp-cloud through version 5.10.0 and is accessible via P [truncated]
Authenticated users can access repositories from other workspaces in Jpom through 2.11.12 due to a failure in validating workspace ownership when resolving repositoryId on the /build/branch-list endpoint. This vulnerability allows for unauthorized repository access and enumeration. Defenders should verify and remediate this vulnerability, focusing on restricting access to repository identifiers and ensuri [truncated]
A weakness has been identified in dromara orion-visor up to 2.5.7. Affected by this issue is the function ExposeApiAspect.beforeExposeApi of the file ExposeApiAspect.java. Executing a manipulation can lead to hard-coded credentials. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an [truncated]
CVE-2026-69102 debrief based on the supplied source corpus. The vulnerability is a critical unauthorized access issue in MaxKey due to a hard-coded JWT signing secret. This allows unauthenticated attackers to forge valid JWT tokens and authenticate as any user by exploiting the password-skipped login endpoint. Defenders and administrators of MaxKey deployments should assess exposure and prioritize remedia [truncated]
CVE-2026-69100 is a remote code execution vulnerability in LAMP Rapid Development Platform through version 5.6.2, fixed in commit 84b0c27. The vulnerability is located in GlueFactory and allows attackers to execute unsandboxed Groovy scripts from database template fields without compilation restrictions or whitelisting. This could lead to arbitrary code execution and OS commands on the backend server. Def [truncated]
A remote code execution vulnerability exists in Dromara lamp-cloud versions up to 5.6.2, specifically within the Message Template Handler component. The vulnerability stems from improper neutralization of special elements in the GroovyClassLoader.parseClass function when processing the DefMsgTemplate.content argument. An attacker with low privileges can exploit this template injection weakness remotely wi [truncated]