CVE-2026-38812
Severity CVSS v4.0:
Pending analysis
Type:
CWE-89
SQL Injection
Publication date:
15/06/2026
Last modified:
16/06/2026
Description
RuoYi v4.8.2 is vulnerable to SQL Injection via the /tool/gen/createTable endpoint. The issue affects the code generation module and may allow an authenticated attacker with administrative privileges to access sensitive database information.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL



