VYPR

Vendor CVEs

Jeecg

All CVEs

102 total · sorted by risk
  • CVE-2026-58377HigJun 30, 2026
    risk 0.00cvss 8.1epss 0.00

    JeecgBoot through 3.9.2 contains a broken access control vulnerability that allows authenticated low-privilege users to perform full create, read, update, and delete operations on OpenAPI credentials by accessing the OpenApiAuthController and OpenApiPermissionController…

  • CVE-2026-58375HigJun 30, 2026
    risk 0.00cvss 7.5epss 0.00

    JimuReport through 2.5.0 exposes the POST /jmreport/auto/export endpoint without authentication: the handler is annotated @JimuNoLoginRequired, so JimuReportTokenInterceptor skips all authentication and authorization, and the export service streams the rendered report for any…

Page 3 of 3