Lamp Cloud Dromara Lamp Cloud

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Dromara Lamp Cloud.

By the Year

In 2026 there have been 4 vulnerabilities in Dromara Lamp Cloud with an average score of 6.4 out of ten.

Year Vulnerabilities Average Score
2026 4 6.35

It may take a day or so for new Lamp Cloud vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Dromara Lamp Cloud Security Vulnerabilities

lamp-cloud <=5.10.0 Path Traversal via FileChunkController (chunk-check)
CVE-2026-19758 6.9 - Medium - August 13, 2026

A vulnerability was determined in dromara lamp-cloud up to 5.10.0. This issue affects some unknown processing of the file FileChunkController.java of the component chunk-check endpoint. Executing a manipulation of the argument Name can lead to path traversal. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.

Directory traversal

Dromara lamp-cloud 5.10.0 File-Upload Controller path traversal (CVE-2026-19757)
CVE-2026-19757 6.9 - Medium - August 13, 2026

A vulnerability was found in Dromara lamp-cloud up to 5.10.0. This vulnerability affects unknown code of the file FileAnyoneController.java of the component File-Upload Controller. Performing a manipulation of the argument bucket/bizType results in path traversal. The attack can be initiated remotely. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.

Directory traversal

Dromara lamp-cloud <=5.10.0 Path Traversal in Code Generator
CVE-2026-19756 5.3 - Medium - August 13, 2026

A vulnerability has been found in Dromara lamp-cloud up to 5.10.0. This affects an unknown part of the file DefGenProjectController.java of the component Code Generator. Such manipulation of the argument outputDir/parent/projectPrefix leads to path traversal. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

Directory traversal

Dromara lamp-cloud 5.6.2 template injection via GroovyClassLoader.parseClass
CVE-2026-9498 6.3 - Medium - May 25, 2026

A vulnerability has been found in Dromara lamp-cloud up to 5.6.2. Impacted is the function GroovyClassLoader.parseClass of the component Message Template Handler. Such manipulation of the argument DefMsgTemplate.content leads to improper neutralization of special elements used in a template engine. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

1336

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Dromara Lamp Cloud or by Dromara? Click the Watch button to subscribe.

Dromara
Vendor

subscribe