Vulnerability index

Browse CVEs

22 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Jsherp CRITICAL 9.8
CVE-2026-1546

A security vulnerability has been detected in jishenghua jshERP up to 3.6. The impacted element is the function getBillItemByParam of the file /jshER…

Fix: after 3.6
Fix from $2,300 2026-01-28
Jsherp CRITICAL 9.8
CVE-2025-51744

An issue was discovered in jishenghua JSH_ERP 2.3.1. The /user/addUser endpoint is vulnerable to fastjson deserialization attacks.

Fix: after 2.3.1
Fix from $2,300 2025-11-25
Jsherp CRITICAL 9.8
CVE-2025-51745

An issue was discovered in jishenghua JSH_ERP 2.3.1. The /role/addcan endpoint is vulnerable to fastjson deserialization attacks.

Fix: after 2.3.1
Fix from $2,300 2025-11-25
Jsherp CRITICAL 9.8
CVE-2025-51746

An issue was discovered in jishenghua JSH_ERP 2.3.1. The /serialNumber/addSerialNumber endpoint is vulnerable to fastjson deserialization attacks.

Fix: after 2.3.1
Fix from $2,300 2025-11-25
Jsherp CRITICAL 9.8
CVE-2025-51743

An issue was discovered in jishenghua JSH_ERP 2.3.1. The /materialCategory/addMaterialCategory endpoint is vulnerable to fastjson deserialization att…

Fix: after 2.3.1
Fix from $2,300 2025-11-25
Jsherp CRITICAL 9.8
CVE-2025-51742

An issue was discovered in jishenghua JSH_ERP 2.3.1. The /material/getMaterialEnableSerialNumberList endpoint passes the search query parameter direc…

Fix: after 2.3.1
Fix from $2,300 2025-11-25
Jsherp HIGH 7.5
CVE-2025-60800

Incorrect access control in the /jshERP-boot/user/info interface of jshERP up to commit 90c411a allows attackers to access sensitive information via …

Fix: 2025-08-07+
Fix from $1,950 2025-10-28
Jsherp HIGH 8.2
CVE-2025-60801

jshERP up to commit fbda24da was discovered to contain an unauthenticated remote code execution (RCE) vulnerability via the jsh_erp function.

Fix: 2025-08-14+
Fix from $1,950 2025-10-24
Jsherp MEDIUM 5.3
CVE-2025-55371

Incorrect access control in the component /controller/PersonController.java of jshERP v3.5 allows unauthorized attackers to obtain all the informatio…

No fix yet
Fix from $1,600 2025-08-21
Jsherp HIGH 8.8
CVE-2025-55368

Incorrect access control in the component \controller\RoleController.java of jshERP v3.5 allows unauthorized attackers to arbitrarily modify the supp…

No fix yet
Fix from $1,950 2025-08-21
Jsherp HIGH 8.8
CVE-2025-55370

Incorrect access control in the component \controller\ResourceController.java of jshERP v3.5 allows unauthorized attackers to obtain all the correspo…

No fix yet
Fix from $1,950 2025-08-21
Jsherp MEDIUM 5.3
CVE-2025-55366

Incorrect access control in the component \controller\UserController.java of jshERP v3.5 allows attackers to arbitrarily reset user account passwords…

No fix yet
Fix from $1,600 2025-08-21
Jsherp MEDIUM 5.3
CVE-2025-55367

Incorrect access control in the component \controller\SupplierController.java of jshERP v3.5 allows unauthorized attackers to arbitrarily modify the …

No fix yet
Fix from $1,600 2025-08-21
Jsherp MEDIUM 5.4
CVE-2025-8840

A vulnerability was determined in jshERP up to 3.5. Affected is an unknown function of the file /jshERP-boot/user/deleteBatch of the component Endpoi…

No fix yet
Fix from $1,600 2025-08-11
Jsherp HIGH 8.8
CVE-2025-8839

A vulnerability was found in jshERP up to 3.5. This issue affects some unknown processing of the file /jshERP-boot/user/addUser of the component Endp…

No fix yet
Fix from $1,950 2025-08-11
Jsherp MEDIUM 6.5
CVE-2025-7948

A vulnerability classified as problematic was found in jshERP up to 3.5. Affected by this vulnerability is an unknown functionality of the file /jshE…

Fix: after 3.5
Fix from $1,600 2025-07-22
Jsherp HIGH 8.1
CVE-2025-7947

A vulnerability classified as critical has been found in jshERP up to 3.5. Affected is an unknown function of the file /user/delete of the component …

Fix: after 3.5
Fix from $1,950 2025-07-22
Jsherp HIGH 7.2
CVE-2025-7566

A vulnerability has been found in jshERP up to 3.5 and classified as critical. This vulnerability affects the function exportExcelByParam of the file…

Fix: after 3.5
Fix from $1,950 2025-07-14
Jsherp CRITICAL 9.8
CVE-2024-24003

jshERP v3.3 is vulnerable to SQL Injection. The com.jsh.erp.controller.DepotHeadController: com.jsh.erp.utils.BaseResponseInfo findInOutMaterialCount…

No fix yet
Fix from $2,300 2024-02-08
Jsherp CRITICAL 9.8
CVE-2024-24001

jshERP v3.3 is vulnerable to SQL Injection. via the com.jsh.erp.controller.DepotHeadController: com.jsh.erp.utils.BaseResponseInfo findallocationDeta…

No fix yet
Fix from $2,300 2024-02-07
Jsherp CRITICAL 9.8
CVE-2024-24002

jshERP v3.3 is vulnerable to SQL Injection. The com.jsh.erp.controller.MaterialController: com.jsh.erp.utils.BaseResponseInfo getListWithStock() func…

No fix yet
Fix from $2,300 2024-02-07
Jsherp CRITICAL 9.8
CVE-2024-24004

jshERP v3.3 is vulnerable to SQL Injection. The com.jsh.erp.controller.DepotHeadController: com.jsh.erp.utils.BaseResponseInfo findInOutDetail() func…

No fix yet
Fix from $2,300 2024-02-07