VYPR

Jeecgboot

by Jeecg

Source repositories

CVEs (83)

  • CVE-2026-11502LowJun 8, 2026
    risk 0.13cvss 3.1epss 0.00

    A weakness has been identified in JeecgBoot up to 3.9.2. Impacted is the function HttpServletResponse.sendRedirect of the file jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/system/controller/ThirdLoginController.java of the component Third-Party Login.…

  • CVE-2026-11464LowJun 7, 2026
    risk 0.13cvss 3.1epss 0.00

    A vulnerability was identified in JeecgBoot up to 3.9.2. Affected by this vulnerability is the function queryPageList of the file src\main\java\org\jeecg\modules\system\controller\SysUserController.java of the component User List Endpoint. The manipulation of the argument salt…

  • CVE-2026-58377HigJun 30, 2026
    risk 0.00cvss 8.1epss 0.00

    JeecgBoot through 3.9.2 contains a broken access control vulnerability that allows authenticated low-privilege users to perform full create, read, update, and delete operations on OpenAPI credentials by accessing the OpenApiAuthController and OpenApiPermissionController…

Page 5 of 5