Vulnerability index

Browse CVEs

12 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Jeesite HIGH 8.1
CVE-2026-3405

A vulnerability has been found in thinkgem JeeSite up to 5.15.1. The affected element is an unknown function of the component Connection Handler. The…

Fix: after 5.15.1
Fix from $1,950 2026-03-02
Jeesite HIGH 8.1
CVE-2026-3404

A flaw has been found in thinkgem JeeSite up to 5.15.1. Impacted is an unknown function of the file /com/jeesite/common/shiro/cas/CasOutHandler.java …

Fix: after 5.15.1
Fix from $1,950 2026-03-02
Jeesite MEDIUM 5.4
CVE-2025-7865

A vulnerability was found in thinkgem JeeSite up to 5.12.0. It has been declared as problematic. This vulnerability affects the function xssFilter of…

Fix: after 5.12.0
Fix from $1,600 2025-07-20
Jeesite MEDIUM 5.4
CVE-2025-7864

A vulnerability was found in thinkgem JeeSite up to 5.12.0. It has been classified as critical. This affects the function Upload of the file src/main…

Fix: 5.12.1+
Fix from $1,600 2025-07-20
Jeesite HIGH 8.8
CVE-2025-7759

A vulnerability was identified in thinkgem JeeSite up to 5.12.0. This vulnerability affects unknown code of the file modules/core/src/main/java/com/j…

Fix: 5.12.1+
Fix from $1,950 2025-07-17
Jeesite HIGH 8.8
CVE-2025-5186

A vulnerability was found in thinkgem JeeSite up to 5.11.1. It has been rated as critical. Affected by this issue is the function ResourceLoader.getR…

Fix: after 5.11.1
Fix from $1,950 2025-05-26
Jeesite MEDIUM 6.1
CVE-2024-8112

A vulnerability was found in thinkgem JeeSite 5.3. It has been rated as problematic. This issue affects some unknown processing of the file /js/a/log…

No fix yet
Fix from $1,600 2024-08-23
Jeesite MEDIUM 5.4
CVE-2023-38991

An issue in the delete function in the ActModelController class of jeesite v1.2.6 allows authenticated attackers to arbitrarily delete models created…

No fix yet
Fix from $1,600 2023-08-04
Jeesite CRITICAL 9.8
CVE-2023-34601

Jeesite before commit 10742d3 was discovered to contain a SQL injection vulnerability via the component ${businessTable} at /act/ActDao.xml.

Fix: 2023-05-27+
Fix from $2,300 2023-06-22
Jeesite CRITICAL 9.8
CVE-2020-19229

Jeesite 1.2.7 uses the apache shiro version 1.2.3 affected by CVE-2016-4437. Because of this version of the java deserialization vulnerability, an at…

No fix yet
Fix from $2,300 2022-04-05
Jeesite MEDIUM 6.5
CVE-2019-1010201

Jeesite 1.2.7 is affected by: SQL Injection. The impact is: sensitive information disclosure. The component is: updateProcInsIdByBusinessId() functio…

Mitigation only
Fix from $1,600 2019-07-23
Jeesite MEDIUM 6.5
CVE-2019-1010202

Jeesite 1.2.7 is affected by: XML External Entity (XXE). The impact is: sensitive information disclosure. The component is: convertToModel() function…

No fix yet
Fix from $1,600 2019-07-23