← Back

Roothub

roothub

6 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Roothub
roothub

CVEs (6)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Roothub
1Roothub
Apr 29, 2026
Jul 26, 2025
2.0 LOW· v4
6.1 MEDIUM· v3
4.0 MEDIUM· v2
A vulnerability was found in Roothub up to 2.6. It has been declared as problematic. Affected by this vulnerability is the function Edit of the file src/main/java/cn/roothub/web/admin/SystemConfigAdminController.java. Th...Show more
A vulnerability was found in Roothub up to 2.6. It has been declared as problematic. Affected by this vulnerability is the function Edit of the file src/main/java/cn/roothub/web/admin/SystemConfigAdminController.java. The manipulation leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.Show less
1Roothub
1Roothub
May 1, 2025
May 7, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Roothub v2.6 was discovered to contain a SQL injection vulnerability via the nodeTitle parameter in the parentNode() function..
1Roothub
1Roothub
May 1, 2025
May 7, 2024
N/A· v4
6.3 MEDIUM· v3
N/A· v2
Roothub v2.6 was discovered to contain a SQL injection vulnerability via the topic parameter in the list() function.
1Roothub
1Roothub
May 1, 2025
May 7, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Roothub v2.5 was discovered to contain an arbitrary file upload vulnerability via the customPath parameter in the upload() function. This vulnerability allows attackers to execute arbitrary code via a crafted JSP file.
1Roothub
1Roothub
Jun 17, 2025
May 6, 2024
N/A· v4
6.3 MEDIUM· v3
N/A· v2
Roothub v2.6 was discovered to contain a SQL injection vulnerability via the 's' parameter in the search() function.
1Roothub
1Roothub
Nov 21, 2024
Apr 13, 2022
N/A· v4
8.0 HIGH· v3
6.0 MEDIUM· v2
Directory Traversal vulnerability in file cn/roothub/store/FileSystemStorageService in function store in Roothub 2.6.0 allows remote attackers with low privlege to arbitrarily upload files via /common/upload API, which c...Show more
Directory Traversal vulnerability in file cn/roothub/store/FileSystemStorageService in function store in Roothub 2.6.0 allows remote attackers with low privlege to arbitrarily upload files via /common/upload API, which could lead to remote arbitrary code execution.Show less