Jeecg
Products
15- 83 CVEs
- 10 CVEs
- 7 CVEs
- 2 CVEs
- 2 CVEs
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 0 CVEs
- 0 CVEs
Recent CVEs
102| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-48307 | Cri | 0.67 | 9.8 | 0.44 | Oct 31, 2024 | JeecgBoot v3.7.1 was discovered to contain a SQL injection vulnerability via the component /onlDragDatasetHead/getTotalData. | ||
| CVE-2023-49442 | Cri | 0.67 | 9.8 | 0.39 | Jan 3, 2024 | Deserialization of Untrusted Data in jeecgFormDemoController in JEECG 4.0 and earlier allows attackers to run arbitrary code via crafted POST request. | ||
| CVE-2023-34659 | Cri | 0.65 | 9.8 | 0.12 | Jun 16, 2023 | jeecg-boot 3.5.0 and 3.5.1 have a SQL injection vulnerability the id parameter of the /jeecg-boot/jmreport/show interface. | ||
| CVE-2024-43028 | Cri | 0.64 | 9.8 | 0.02 | Apr 1, 2026 | A command injection vulnerability in the component /jmreport/show of jeecg boot v3.0.0 to v3.5.3 allows attackers to execute arbitrary code via a crafted HTTP request. | ||
| CVE-2024-40489 | Cri | 0.64 | 9.8 | 0.01 | Apr 1, 2026 | There is an injection vulnerability in jeecg boot versions 3.0.0 to 3.5.3 due to lax character filtering, which allows attackers to execute arbitrary code on components through specially crafted HTTP requests. | ||
| CVE-2025-66913 | Cri | 0.64 | 9.8 | 0.01 | Jan 8, 2026 | JimuReport thru version 2.1.3 is vulnerable to remote code execution when processing user-controlled H2 JDBC URLs. The application passes the attacker-supplied JDBC URL directly to the H2 driver, allowing the use of certain directives to execute arbitrary Java code. A different… | ||
| CVE-2024-50640 | Cri | 0.64 | 9.8 | 0.01 | Aug 20, 2025 | jeewx-boot 1.3 has an authentication bypass vulnerability in the preHandle function | ||
| CVE-2024-44893 | Cri | 0.64 | 9.8 | 0.01 | Sep 10, 2024 | An issue in the component /jeecg-boot/jmreport/dict/list of JimuReport v1.7.8 allows attacker to escalate privileges via a crafted GET request. | ||
| CVE-2023-41544 | Cri | 0.64 | 9.8 | 0.03 | Dec 30, 2023 | SSTI injection vulnerability in jeecg-boot version 3.5.3, allows remote attackers to execute arbitrary code via crafted HTTP request to the /jmreport/loadTableData component. | ||
| CVE-2023-41543 | Cri | 0.64 | 9.8 | 0.01 | Dec 30, 2023 | SQL injection vulnerability in jeecg-boot v3.5.3, allows remote attackers to escalate privileges and obtain sensitive information via the component /sys/replicate/check. | ||
| CVE-2023-41542 | Cri | 0.64 | 9.8 | 0.01 | Dec 30, 2023 | SQL injection vulnerability in jeecg-boot version 3.5.3, allows remote attackers to escalate privileges and obtain sensitive information via the jmreport/qurestSql component. | ||
| CVE-2023-42268 | Cri | 0.64 | 9.8 | 0.01 | Sep 8, 2023 | Jeecg boot up to v3.5.3 was discovered to contain a SQL injection vulnerability via the component /jeecg-boot/jmreport/show. | ||
| CVE-2022-22881 | Cri | 0.64 | 9.8 | 0.01 | Feb 16, 2022 | Jeecg-boot v3.0 was discovered to contain a SQL injection vulnerability via the code parameter in /sys/user/queryUserComponentData. | ||
| CVE-2022-22880 | Cri | 0.64 | 9.8 | 0.01 | Feb 16, 2022 | Jeecg-boot v3.0 was discovered to contain a SQL injection vulnerability via the code parameter in /jeecg-boot/sys/user/queryUserByDepId. | ||
| CVE-2020-28088 | Cri | 0.64 | 9.8 | 0.02 | Aug 6, 2021 | An arbitrary file upload vulnerability in /jeecg-boot/sys/common/upload of jeecg-boot CMS 2.3 allows attackers to execute arbitrary code. | ||
| CVE-2020-23083 | Cri | 0.64 | 9.8 | 0.04 | May 3, 2021 | Unrestricted File Upload in JEECG v4.0 and earlier allows remote attackers to execute arbitrary code or gain privileges by uploading a crafted file to the component "jeecgFormDemoController.do?commonUpload". | ||
| CVE-2023-38992 | Cri | 0.63 | 9.8 | 0.74 | Jul 28, 2023 | jeecg-boot v3.5.1 was discovered to contain a SQL injection vulnerability via the title parameter at /sys/dict/loadTreeData. | ||
| CVE-2026-36418 | Cri | 0.59 | 9.1 | 0.00 | Jun 17, 2026 | JimuReport versions 2.3.4 and below are vulnerable to remote code execution due to improper handling of Aviator expressions. The /jmreport/executeSelectApi endpoint passes user-supplied input directly to the Aviator expression engine without adequate validation allowing… | ||
| CVE-2023-40989 | Cri | 0.57 | 9.8 | 0.02 | Sep 22, 2023 | SQL injection vulnerbility in jeecgboot jeecg-boot v 3.0, 3.5.3 that allows a remote attacker to execute arbitrary code via a crafted request to the report/jeecgboot/jmreport/queryFieldBySql component. | ||
| CVE-2023-24789 | Hig | 0.57 | 8.8 | 0.01 | Mar 6, 2023 | jeecg-boot v3.4.4 was discovered to contain an authenticated SQL injection vulnerability via the building block report component. |
- risk 0.67cvss 9.8epss 0.44
JeecgBoot v3.7.1 was discovered to contain a SQL injection vulnerability via the component /onlDragDatasetHead/getTotalData.
- risk 0.67cvss 9.8epss 0.39
Deserialization of Untrusted Data in jeecgFormDemoController in JEECG 4.0 and earlier allows attackers to run arbitrary code via crafted POST request.
- risk 0.65cvss 9.8epss 0.12
jeecg-boot 3.5.0 and 3.5.1 have a SQL injection vulnerability the id parameter of the /jeecg-boot/jmreport/show interface.
- risk 0.64cvss 9.8epss 0.02
A command injection vulnerability in the component /jmreport/show of jeecg boot v3.0.0 to v3.5.3 allows attackers to execute arbitrary code via a crafted HTTP request.
- risk 0.64cvss 9.8epss 0.01
There is an injection vulnerability in jeecg boot versions 3.0.0 to 3.5.3 due to lax character filtering, which allows attackers to execute arbitrary code on components through specially crafted HTTP requests.
- risk 0.64cvss 9.8epss 0.01
JimuReport thru version 2.1.3 is vulnerable to remote code execution when processing user-controlled H2 JDBC URLs. The application passes the attacker-supplied JDBC URL directly to the H2 driver, allowing the use of certain directives to execute arbitrary Java code. A different…
- risk 0.64cvss 9.8epss 0.01
jeewx-boot 1.3 has an authentication bypass vulnerability in the preHandle function
- risk 0.64cvss 9.8epss 0.01
An issue in the component /jeecg-boot/jmreport/dict/list of JimuReport v1.7.8 allows attacker to escalate privileges via a crafted GET request.
- risk 0.64cvss 9.8epss 0.03
SSTI injection vulnerability in jeecg-boot version 3.5.3, allows remote attackers to execute arbitrary code via crafted HTTP request to the /jmreport/loadTableData component.
- risk 0.64cvss 9.8epss 0.01
SQL injection vulnerability in jeecg-boot v3.5.3, allows remote attackers to escalate privileges and obtain sensitive information via the component /sys/replicate/check.
- risk 0.64cvss 9.8epss 0.01
SQL injection vulnerability in jeecg-boot version 3.5.3, allows remote attackers to escalate privileges and obtain sensitive information via the jmreport/qurestSql component.
- risk 0.64cvss 9.8epss 0.01
Jeecg boot up to v3.5.3 was discovered to contain a SQL injection vulnerability via the component /jeecg-boot/jmreport/show.
- risk 0.64cvss 9.8epss 0.01
Jeecg-boot v3.0 was discovered to contain a SQL injection vulnerability via the code parameter in /sys/user/queryUserComponentData.
- risk 0.64cvss 9.8epss 0.01
Jeecg-boot v3.0 was discovered to contain a SQL injection vulnerability via the code parameter in /jeecg-boot/sys/user/queryUserByDepId.
- risk 0.64cvss 9.8epss 0.02
An arbitrary file upload vulnerability in /jeecg-boot/sys/common/upload of jeecg-boot CMS 2.3 allows attackers to execute arbitrary code.
- risk 0.64cvss 9.8epss 0.04
Unrestricted File Upload in JEECG v4.0 and earlier allows remote attackers to execute arbitrary code or gain privileges by uploading a crafted file to the component "jeecgFormDemoController.do?commonUpload".
- risk 0.63cvss 9.8epss 0.74
jeecg-boot v3.5.1 was discovered to contain a SQL injection vulnerability via the title parameter at /sys/dict/loadTreeData.
- risk 0.59cvss 9.1epss 0.00
JimuReport versions 2.3.4 and below are vulnerable to remote code execution due to improper handling of Aviator expressions. The /jmreport/executeSelectApi endpoint passes user-supplied input directly to the Aviator expression engine without adequate validation allowing…
- risk 0.57cvss 9.8epss 0.02
SQL injection vulnerbility in jeecgboot jeecg-boot v 3.0, 3.5.3 that allows a remote attacker to execute arbitrary code via a crafted request to the report/jeecgboot/jmreport/queryFieldBySql component.
- risk 0.57cvss 8.8epss 0.01
jeecg-boot v3.4.4 was discovered to contain an authenticated SQL injection vulnerability via the building block report component.