VYPR
Vendor

Guojusoft

Products
2
CVEs
3
Across products
3
Status
Private

Products

2

Recent CVEs

3
  • CVE-2020-23083CriMay 3, 2021
    risk 0.64cvss 9.8epss 0.04

    Unrestricted File Upload in JEECG v4.0 and earlier allows remote attackers to execute arbitrary code or gain privileges by uploading a crafted file to the component "jeecgFormDemoController.do?commonUpload".

  • CVE-2024-57606HigFeb 7, 2025
    risk 0.49cvss 7.5epss 0.01

    SQL injection vulnerability in Beijing Guoju Information Technology Co., Ltd JeecgBoot v.3.7.2 allows a remote attacker to obtain sensitive information via the getTotalData component.

  • CVE-2025-51825MedAug 22, 2025
    risk 0.35cvss 6.5epss 0.00

    JeecgBoot versions from 3.4.3 up to 3.8.0 were found to contain a SQL injection vulnerability in the /jeecg-boot/online/cgreport/head/parseSql endpoint, which allows bypassing SQL blacklist restrictions.