CVE-2026-108802 | y_project RuoYi up to 4.8.3 Dictionary Data Drawer Preview /system/dict/data/add renderDrawer cssClass cross site scripting

SecurityVulns

A vulnerability categorized as problematic has been discovered in y_project RuoYi up to 4.8.3. This affects the function renderDrawer of the file /system/dict/data/add of the component Dictionary Data Drawer Preview. Executing a manipulation of the argument cssClass can lead to cross site scripting.

This vulnerability appears as CVE-2026-108802. The attack may be performed from remote. In addition, an exploit is available.

The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More