Vulnerability index

Browse CVEs

62 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2024-40489 There is an injection vulnerability in jeecg boot versions 3.0.0 to 3.5.3 due to lax character filtering, which allows attackers to execute arbitrary… Jeecg Boot after 3.5.3 Fix from $2,3002026-04-01 CRITICAL 9.8 CVE-2024-43028 A command injection vulnerability in the component /jmreport/show of jeecg boot v3.0.0 to v3.5.3 allows attackers to execute arbitrary code via a cra… Jeecg Boot after 3.5.3 Fix from $2,3002026-04-01 MEDIUM 6.5 CVE-2026-2945 A weakness has been identified in JeecgBoot 3.9.0. Affected by this vulnerability is an unknown functionality of the file /sys/common/uploadImgByHttp… Jeecg Boot No fix yet Fix from $1,6002026-02-22 HIGH 8.8 CVE-2026-2822 A security vulnerability has been detected in JeecgBoot up to 3.9.1. The affected element is an unknown function of the file /jeecgboot/sys/dict/load… Jeecg Boot after 3.9.1 Fix from $1,9502026-02-20 HIGH 7.5 CVE-2026-2555 A weakness has been identified in JeecgBoot 3.9.1. This vulnerability affects the function importDocumentFromZip of the file org/jeecg/modules/airag/… Jeecg Boot No fix yet Fix from $1,9502026-02-16 HIGH 8.8 CVE-2026-1746 A vulnerability was identified in JeecgBoot 3.9.0. This vulnerability affects unknown code of the file /JeecgBoot/sys/api/loadDictItemByKeyword of th… Jeecg Boot No fix yet Fix from $1,9502026-02-02 CRITICAL 9.8 CVE-2025-66913 JimuReport thru version 2.1.3 is vulnerable to remote code execution when processing user-controlled H2 JDBC URLs. The application passes the attacke… Jimureport after 2.1.3 Fix from $2,3002026-01-08 HIGH 7.5 CVE-2025-15126 A weakness has been identified in JeecgBoot up to 3.9.0. Affected by this vulnerability is the function getPositionUserList of the file /sys/position… Jeecg Boot after 3.9.0 Fix from $1,9502025-12-28 HIGH 8.1 CVE-2025-14909 A weakness has been identified in JeecgBoot up to 3.9.0. The impacted element is the function SysUserOnlineController of the file jeecg-boot/jeecg-mo… Jeecg Boot after 3.9.0 Fix from $1,9502025-12-19 HIGH 8.1 CVE-2025-14908 A security flaw has been discovered in JeecgBoot up to 3.9.0. The affected element is an unknown function of the file jeecg-boot/jeecg-module-system/… Jeecg Boot after 3.9.0 Fix from $1,9502025-12-19 MEDIUM 6.3 CVE-2025-61189 Jeecgboot versions 3.8.2 and earlier are affected by a path traversal vulnerability. The endpoint is /sys/comment/addFile. This vulnerability allows … Jeecg Boot after 3.8.2 Fix from $1,6002025-10-01 MEDIUM 6.3 CVE-2025-61188 Jeecgboot versions 3.8.2 and earlier are affected by a path traversal vulnerability. This vulnerability allows attackers to upload files with system-… Jeecg Boot after 3.8.2 Fix from $1,6002025-10-01 MEDIUM 6.5 CVE-2025-10981 A vulnerability was detected in JeecgBoot up to 3.8.2. This impacts an unknown function of the file /sys/tenant/exportXls. Performing manipulation re… Jeecg Boot after 3.8.2 Fix from $1,6002025-09-26 MEDIUM 6.5 CVE-2025-10980 A security vulnerability has been detected in JeecgBoot up to 3.8.2. This affects an unknown function of the file /sys/position/exportXls. Such manip… Jeecg Boot after 3.8.2 Fix from $1,6002025-09-26 MEDIUM 6.5 CVE-2025-10978 A security flaw has been discovered in JeecgBoot up to 3.8.2. The affected element is an unknown function of the file /sys/user/exportXls of the comp… Jeecg Boot after 3.8.2 Fix from $1,6002025-09-25 MEDIUM 6.5 CVE-2025-10979 A weakness has been identified in JeecgBoot up to 3.8.2. The impacted element is an unknown function of the file /sys/role/exportXls. This manipulati… Jeecg Boot after 3.8.2 Fix from $1,6002025-09-25 MEDIUM 5.3 CVE-2025-10977 A vulnerability was identified in JeecgBoot up to 3.8.2. Impacted is an unknown function of the file /sys/tenant/deleteBatch. The manipulation of the… Jeecg Boot after 3.8.2 Fix from $1,6002025-09-25 MEDIUM 5.3 CVE-2025-10976 A vulnerability was determined in JeecgBoot up to 3.8.2. This issue affects some unknown processing of the file /api/getDepartUserList. Executing man… Jeecg Boot after 3.8.2 Fix from $1,6002025-09-25 CRITICAL 9.8 CVE-2025-10771 A vulnerability was determined in jeecgboot JimuReport up to 2.1.2. Affected is an unknown function of the file /drag/onlDragDataSource/testConnectio… Jimureport after 2.1.2 Fix from $2,3002025-09-21 MEDIUM 6.5 CVE-2025-10770 A vulnerability was found in jeecgboot JimuReport up to 2.1.2. This impacts an unknown function of the file /drag/onlDragDataSource/testConnection of… Jimureport after 2.1.2 Fix from $1,6002025-09-21 HIGH 8.8 CVE-2025-10707 A weakness has been identified in JeecgBoot up to 3.8.2. Affected is an unknown function of the file /message/sysMessageTemplate/sendMsg. Executing m… Jeecg Boot after 3.8.2 Fix from $1,9502025-09-19 MEDIUM 6.5 CVE-2025-10319 A security flaw has been discovered in JeecgBoot up to 3.8.2. Affected by this issue is some unknown functionality of the file /sys/tenant/exportLog … Jeecg Boot after 3.8.2 Fix from $1,6002025-09-12 HIGH 8.8 CVE-2025-10318 A vulnerability was identified in JeecgBoot up to 3.8.2. Affected by this vulnerability is an unknown functionality of the file /api/system/sendWebSo… Jeecg Boot after 3.8.2 Fix from $1,9502025-09-12 CRITICAL 9.8 CVE-2025-8963 A vulnerability was determined in jeecgboot JimuReport up to 2.1.1. Affected by this issue is some unknown functionality of the file /drag/onlDragDat… Jimureport after 2.1.1 Fix from $2,3002025-08-14 HIGH 7.5 CVE-2025-4533 A vulnerability classified as problematic was found in JeecgBoot up to 3.8.0. This vulnerability affects the function unzipFile of the file /jeecg-bo… Jeecg Boot after 3.8.0 Fix from $1,9502025-05-11 CRITICAL 9.8 CVE-2024-48307EPSS 44% JeecgBoot v3.7.1 was discovered to contain a SQL injection vulnerability via the component /onlDragDatasetHead/getTotalData. Jeecg Boot No fix yet Fix from $2,3002024-10-31 CRITICAL 9.8 CVE-2024-44893 An issue in the component /jeecg-boot/jmreport/dict/list of JimuReport v1.7.8 allows attacker to escalate privileges via a crafted GET request. Jimureport No fix yet Fix from $2,3002024-09-10 CRITICAL 9.8 CVE-2023-49442EPSS 39% Deserialization of Untrusted Data in jeecgFormDemoController in JEECG 4.0 and earlier allows attackers to run arbitrary code via crafted POST request. Jeecg after 4.0 Fix from $2,3002024-01-03 CRITICAL 9.8 CVE-2023-41544 SSTI injection vulnerability in jeecg-boot version 3.5.3, allows remote attackers to execute arbitrary code via crafted HTTP request to the /jmreport… Jeecg Boot after 3.5.3 Fix from $2,3002023-12-30 CRITICAL 9.8 CVE-2023-41542 SQL injection vulnerability in jeecg-boot version 3.5.3, allows remote attackers to escalate privileges and obtain sensitive information via the jmre… Jeecg Boot after 3.5.3 Fix from $2,3002023-12-30