Vulnerability index

Browse CVEs

62 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Jeecg Boot CRITICAL 9.8
CVE-2024-40489

There is an injection vulnerability in jeecg boot versions 3.0.0 to 3.5.3 due to lax character filtering, which allows attackers to execute arbitrary…

Fix: after 3.5.3
Fix from $2,300 2026-04-01
Jeecg Boot CRITICAL 9.8
CVE-2024-43028

A command injection vulnerability in the component /jmreport/show of jeecg boot v3.0.0 to v3.5.3 allows attackers to execute arbitrary code via a cra…

Fix: after 3.5.3
Fix from $2,300 2026-04-01
Jeecg Boot MEDIUM 6.5
CVE-2026-2945

A weakness has been identified in JeecgBoot 3.9.0. Affected by this vulnerability is an unknown functionality of the file /sys/common/uploadImgByHttp…

No fix yet
Fix from $1,600 2026-02-22
Jeecg Boot HIGH 8.8
CVE-2026-2822

A security vulnerability has been detected in JeecgBoot up to 3.9.1. The affected element is an unknown function of the file /jeecgboot/sys/dict/load…

Fix: after 3.9.1
Fix from $1,950 2026-02-20
Jeecg Boot HIGH 7.5
CVE-2026-2555

A weakness has been identified in JeecgBoot 3.9.1. This vulnerability affects the function importDocumentFromZip of the file org/jeecg/modules/airag/…

No fix yet
Fix from $1,950 2026-02-16
Jeecg Boot HIGH 8.8
CVE-2026-1746

A vulnerability was identified in JeecgBoot 3.9.0. This vulnerability affects unknown code of the file /JeecgBoot/sys/api/loadDictItemByKeyword of th…

No fix yet
Fix from $1,950 2026-02-02
Jimureport CRITICAL 9.8
CVE-2025-66913

JimuReport thru version 2.1.3 is vulnerable to remote code execution when processing user-controlled H2 JDBC URLs. The application passes the attacke…

Fix: after 2.1.3
Fix from $2,300 2026-01-08
Jeecg Boot HIGH 7.5
CVE-2025-15126

A weakness has been identified in JeecgBoot up to 3.9.0. Affected by this vulnerability is the function getPositionUserList of the file /sys/position…

Fix: after 3.9.0
Fix from $1,950 2025-12-28
Jeecg Boot HIGH 8.1
CVE-2025-14909

A weakness has been identified in JeecgBoot up to 3.9.0. The impacted element is the function SysUserOnlineController of the file jeecg-boot/jeecg-mo…

Fix: after 3.9.0
Fix from $1,950 2025-12-19
Jeecg Boot HIGH 8.1
CVE-2025-14908

A security flaw has been discovered in JeecgBoot up to 3.9.0. The affected element is an unknown function of the file jeecg-boot/jeecg-module-system/…

Fix: after 3.9.0
Fix from $1,950 2025-12-19
Jeecg Boot MEDIUM 6.3
CVE-2025-61189

Jeecgboot versions 3.8.2 and earlier are affected by a path traversal vulnerability. The endpoint is /sys/comment/addFile. This vulnerability allows …

Fix: after 3.8.2
Fix from $1,600 2025-10-01
Jeecg Boot MEDIUM 6.3
CVE-2025-61188

Jeecgboot versions 3.8.2 and earlier are affected by a path traversal vulnerability. This vulnerability allows attackers to upload files with system-…

Fix: after 3.8.2
Fix from $1,600 2025-10-01
Jeecg Boot MEDIUM 6.5
CVE-2025-10981

A vulnerability was detected in JeecgBoot up to 3.8.2. This impacts an unknown function of the file /sys/tenant/exportXls. Performing manipulation re…

Fix: after 3.8.2
Fix from $1,600 2025-09-26
Jeecg Boot MEDIUM 6.5
CVE-2025-10980

A security vulnerability has been detected in JeecgBoot up to 3.8.2. This affects an unknown function of the file /sys/position/exportXls. Such manip…

Fix: after 3.8.2
Fix from $1,600 2025-09-26
Jeecg Boot MEDIUM 6.5
CVE-2025-10978

A security flaw has been discovered in JeecgBoot up to 3.8.2. The affected element is an unknown function of the file /sys/user/exportXls of the comp…

Fix: after 3.8.2
Fix from $1,600 2025-09-25
Jeecg Boot MEDIUM 6.5
CVE-2025-10979

A weakness has been identified in JeecgBoot up to 3.8.2. The impacted element is an unknown function of the file /sys/role/exportXls. This manipulati…

Fix: after 3.8.2
Fix from $1,600 2025-09-25
Jeecg Boot MEDIUM 5.3
CVE-2025-10977

A vulnerability was identified in JeecgBoot up to 3.8.2. Impacted is an unknown function of the file /sys/tenant/deleteBatch. The manipulation of the…

Fix: after 3.8.2
Fix from $1,600 2025-09-25
Jeecg Boot MEDIUM 5.3
CVE-2025-10976

A vulnerability was determined in JeecgBoot up to 3.8.2. This issue affects some unknown processing of the file /api/getDepartUserList. Executing man…

Fix: after 3.8.2
Fix from $1,600 2025-09-25
Jimureport CRITICAL 9.8
CVE-2025-10771

A vulnerability was determined in jeecgboot JimuReport up to 2.1.2. Affected is an unknown function of the file /drag/onlDragDataSource/testConnectio…

Fix: after 2.1.2
Fix from $2,300 2025-09-21
Jimureport MEDIUM 6.5
CVE-2025-10770

A vulnerability was found in jeecgboot JimuReport up to 2.1.2. This impacts an unknown function of the file /drag/onlDragDataSource/testConnection of…

Fix: after 2.1.2
Fix from $1,600 2025-09-21
Jeecg Boot HIGH 8.8
CVE-2025-10707

A weakness has been identified in JeecgBoot up to 3.8.2. Affected is an unknown function of the file /message/sysMessageTemplate/sendMsg. Executing m…

Fix: after 3.8.2
Fix from $1,950 2025-09-19
Jeecg Boot MEDIUM 6.5
CVE-2025-10319

A security flaw has been discovered in JeecgBoot up to 3.8.2. Affected by this issue is some unknown functionality of the file /sys/tenant/exportLog …

Fix: after 3.8.2
Fix from $1,600 2025-09-12
Jeecg Boot HIGH 8.8
CVE-2025-10318

A vulnerability was identified in JeecgBoot up to 3.8.2. Affected by this vulnerability is an unknown functionality of the file /api/system/sendWebSo…

Fix: after 3.8.2
Fix from $1,950 2025-09-12
Jimureport CRITICAL 9.8
CVE-2025-8963

A vulnerability was determined in jeecgboot JimuReport up to 2.1.1. Affected by this issue is some unknown functionality of the file /drag/onlDragDat…

Fix: after 2.1.1
Fix from $2,300 2025-08-14
Jeecg Boot HIGH 7.5
CVE-2025-4533

A vulnerability classified as problematic was found in JeecgBoot up to 3.8.0. This vulnerability affects the function unzipFile of the file /jeecg-bo…

Fix: after 3.8.0
Fix from $1,950 2025-05-11
Jeecg Boot CRITICAL 9.8
CVE-2024-48307EPSS 44%

JeecgBoot v3.7.1 was discovered to contain a SQL injection vulnerability via the component /onlDragDatasetHead/getTotalData.

No fix yet
Fix from $2,300 2024-10-31
Jimureport CRITICAL 9.8
CVE-2024-44893

An issue in the component /jeecg-boot/jmreport/dict/list of JimuReport v1.7.8 allows attacker to escalate privileges via a crafted GET request.

No fix yet
Fix from $2,300 2024-09-10
Jeecg CRITICAL 9.8
CVE-2023-49442EPSS 39%

Deserialization of Untrusted Data in jeecgFormDemoController in JEECG 4.0 and earlier allows attackers to run arbitrary code via crafted POST request.

Fix: after 4.0
Fix from $2,300 2024-01-03
Jeecg Boot CRITICAL 9.8
CVE-2023-41544

SSTI injection vulnerability in jeecg-boot version 3.5.3, allows remote attackers to execute arbitrary code via crafted HTTP request to the /jmreport…

Fix: after 3.5.3
Fix from $2,300 2023-12-30
Jeecg Boot CRITICAL 9.8
CVE-2023-41542

SQL injection vulnerability in jeecg-boot version 3.5.3, allows remote attackers to escalate privileges and obtain sensitive information via the jmre…

Fix: after 3.5.3
Fix from $2,300 2023-12-30