Ruoyi · Ruoyi · CVE-2026-37216
**Name of the Vulnerable Software and Affected Versions**
Ruoyi version 4.8.2
**Description**
Cross Site Scripting (XSS) occurs at the '/system/notice/add' endpoint. XSS is a type of security flaw that allows an attacker to inject malicious scripts into web pages viewed by other users.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.