Vulnerability index

Browse CVEs

9 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Jeewms HIGH 7.3
CVE-2026-3026

A vulnerability has been found in erzhongxmu JEEWMS 3.7. Affected by this issue is some unknown functionality of the file /plug-in/ueditor/jsp/getRem…

Fix: after 3.7
Fix from $1,950 2026-02-23
Jeewms MEDIUM 6.1
CVE-2026-3027

A vulnerability was found in erzhongxmu JEEWMS up to 3.7. This affects an unknown part of the file src/main/webapp/plug-in/ueditor/jsp/getContent.jsp…

Fix: after 3.7
Fix from $1,600 2026-02-23
Jeewms CRITICAL 9.8
CVE-2024-53499

Jeewms v3.7 was discovered to contain a SQL injection vulnerability via the CgReportController API.

Mitigation only
Fix from $2,300 2025-08-22
Jeewms CRITICAL 9.8
CVE-2025-50901

JeeWMS 771e4f5d0c01ffdeae1671be4cf102b73a3fe644 (2025-05-19) contains incorrect authentication bypass vulnerability, which can lead to arbitrary file…

Mitigation only
Fix from $2,300 2025-08-20
Jeewms MEDIUM 5.5
CVE-2025-29213

A zip slip vulnerability in the component \service\migrate\MigrateForm.java of JEEWMS v3.7 allows attackers to execute arbitrary code via a crafted Z…

No fix yet
Fix from $1,600 2025-04-15
Jeewms HIGH 7.5
CVE-2024-57757

JeeWMS before v2025.01.01 was discovered to contain a permission bypass in the component /interceptors/AuthInterceptor.cava.

Fix: 2025.01.01+
Fix from $1,950 2025-01-15
Jeewms MEDIUM 6.5
CVE-2024-57760

JeeWMS before v2025.01.01 was discovered to contain a SQL injection vulnerability via the ReportId parameter at /core/CGReportDao.java.

Fix: 2025.01.01+
Fix from $1,600 2025-01-15
Jeewms HIGH 7.5
CVE-2024-27765

Directory Traversal vulnerability in Jeewms v.3.7 and before allows a remote attacker to obtain sensitive information via the cgformTemplateControlle…

Fix: after 3.7
Fix from $1,950 2024-03-05
Jeewms CRITICAL 9.8
CVE-2024-27764

An issue in Jeewms v.3.7 and before allows a remote attacker to escalate privileges via the AuthInterceptor component.

Fix: after 3.7
Fix from $2,300 2024-03-05