VYPR

jeecg-boot CMS

by Jeecg

Source repositories

CVEs (24)

  • CVE-2023-34659CriJun 16, 2023
    risk 0.65cvss 9.8epss 0.12

    jeecg-boot 3.5.0 and 3.5.1 have a SQL injection vulnerability the id parameter of the /jeecg-boot/jmreport/show interface.

  • CVE-2024-40489CriApr 1, 2026
    risk 0.64cvss 9.8epss 0.01

    There is an injection vulnerability in jeecg boot versions 3.0.0 to 3.5.3 due to lax character filtering, which allows attackers to execute arbitrary code on components through specially crafted HTTP requests.

  • CVE-2023-41544CriDec 30, 2023
    risk 0.64cvss 9.8epss 0.03

    SSTI injection vulnerability in jeecg-boot version 3.5.3, allows remote attackers to execute arbitrary code via crafted HTTP request to the /jmreport/loadTableData component.

  • CVE-2023-41543CriDec 30, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in jeecg-boot v3.5.3, allows remote attackers to escalate privileges and obtain sensitive information via the component /sys/replicate/check.

  • CVE-2023-41542CriDec 30, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in jeecg-boot version 3.5.3, allows remote attackers to escalate privileges and obtain sensitive information via the jmreport/qurestSql component.

  • CVE-2022-22880CriFeb 16, 2022
    risk 0.64cvss 9.8epss 0.01

    Jeecg-boot v3.0 was discovered to contain a SQL injection vulnerability via the code parameter in /jeecg-boot/sys/user/queryUserByDepId.

  • CVE-2023-38992CriJul 28, 2023
    risk 0.63cvss 9.8epss 0.73

    jeecg-boot v3.5.1 was discovered to contain a SQL injection vulnerability via the title parameter at /sys/dict/loadTreeData.

  • CVE-2023-24789HigMar 6, 2023
    risk 0.57cvss 8.8epss 0.01

    jeecg-boot v3.4.4 was discovered to contain an authenticated SQL injection vulnerability via the building block report component.

  • CVE-2022-47105CriJan 19, 2023
    risk 0.57cvss 9.8epss 0.01

    Jeecg-boot v3.4.4 was discovered to contain a SQL injection vulnerability via the component /sys/dict/queryTableData.

  • CVE-2022-45207CriNov 25, 2022
    risk 0.57cvss 9.8epss 0.01

    Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component updateNullByEmptyString.

  • CVE-2022-45206CriNov 25, 2022
    risk 0.57cvss 9.8epss 0.01

    Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/duplicate/check.

  • CVE-2021-37306HigFeb 3, 2023
    risk 0.49cvss 7.5epss 0.01

    An Insecure Permissions issue in jeecg-boot 2.4.5 and earlier allows remote attackers to gain escalated privilege and view sensitive information via api uri: api uri:/sys/user/checkOnlyUser?username=admin.

  • CVE-2021-37305HigFeb 3, 2023
    risk 0.49cvss 7.5epss 0.04

    An Insecure Permissions issue in jeecg-boot 2.4.5 and earlier allows remote attackers to gain escalated privilege and view sensitive information via api uri: /sys/user/querySysUser?username=admin.

  • CVE-2021-37304HigFeb 3, 2023
    risk 0.49cvss 7.5epss 0.04

    An Insecure Permissions issue in jeecg-boot 2.4.5 allows unauthenticated remote attackers to gain escalated privilege and view sensitive information via the httptrace interface.

  • CVE-2020-28087HigAug 6, 2021
    risk 0.49cvss 7.5epss 0.02

    A SQL injection vulnerability in /jeecg boot/sys/dict/loadtreedata of jeecg-boot CMS 2.3 allows attackers to access sensitive database information.

  • CVE-2023-1454MedMar 17, 2023
    risk 0.44cvss 6.3epss 0.36

    A vulnerability classified as critical has been found in jeecg-boot 3.5.0. This affects an unknown part of the file jmreport/qurestSql. The manipulation of the argument apiSelectId leads to sql injection. It is possible to initiate the attack remotely. The exploit has been…

  • CVE-2023-47467MedNov 22, 2023
    risk 0.42cvss 6.5epss 0.01

    Directory Traversal vulnerability in jeecg-boot v.3.6.0 allows a remote privileged attacker to obtain sensitive information via the file directory structure.

  • CVE-2023-38905MedAug 17, 2023
    risk 0.36cvss 5.5epss 0.00

    SQL injection vulnerability in Jeecg-boot v.3.5.0 and before allows a local attacker to cause a denial of service via the Benchmark, PG_Sleep, DBMS_Lock.Sleep, Waitfor, DECODE, and DBMS_PIPE.RECEIVE_MESSAGE functions.

  • CVE-2023-1784MedMar 31, 2023
    risk 0.35cvss 5.3epss 0.01

    A vulnerability was found in jeecg-boot 3.5.0 and classified as critical. This issue affects some unknown processing of the component API Documentation. The manipulation leads to improper authentication. The attack may be initiated remotely. The exploit has been disclosed to the…

  • CVE-2022-45205MedNov 25, 2022
    risk 0.34cvss 5.3epss 0.01

    Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/dict/queryTableData.

Page 1 of 2