CVE-2026-11502
- EPSS 0.25%
- Veröffentlicht 08.06.2026 09:30:10
- Zuletzt bearbeitet 08.06.2026 14:57:14
A weakness has been identified in JeecgBoot up to 3.9.2. Impacted is the function HttpServletResponse.sendRedirect of the file jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/system/controller/ThirdLoginController.java of the com...
CVE-2026-11464
- EPSS 0.22%
- Veröffentlicht 07.06.2026 22:30:11
- Zuletzt bearbeitet 08.06.2026 14:57:14
A vulnerability was identified in JeecgBoot up to 3.9.2. Affected by this vulnerability is the function queryPageList of the file src\main\java\org\jeecg\modules\system\controller\SysUserController.java of the component User List Endpoint. The manipu...
CVE-2026-10240
- EPSS 0.27%
- Veröffentlicht 01.06.2026 09:16:15
- Zuletzt bearbeitet 01.06.2026 15:15:37
A vulnerability was identified in JeecgBoot up to 3.9.2. The impacted element is an unknown function of the file /airag/airagModel/test. The manipulation of the argument baseUrl leads to server-side request forgery. The attack is possible to be carri...
CVE-2026-10239
- EPSS 0.27%
- Veröffentlicht 01.06.2026 09:16:15
- Zuletzt bearbeitet 01.06.2026 15:15:37
A vulnerability was determined in JeecgBoot up to 3.9.2. The affected element is the function WordUtil.addImage of the file /airag/word/edit. Executing a manipulation can lead to server-side request forgery. The attack can be executed remotely. The e...
CVE-2026-9604
- EPSS 0.22%
- Veröffentlicht 26.05.2026 22:15:15
- Zuletzt bearbeitet 27.05.2026 14:50:47
A vulnerability was detected in JeecgBoot up to 3.9.1. This vulnerability affects unknown code of the component AiragModelController. The manipulation of the argument list/queryById results in improper access controls. The attack can be executed remo...
CVE-2026-9581
- EPSS 0.21%
- Veröffentlicht 26.05.2026 20:30:13
- Zuletzt bearbeitet 28.05.2026 14:16:26
A vulnerability was identified in JeecgBoot up to 3.9.1. The impacted element is an unknown function of the file /sys/comment/add. Such manipulation leads to improper access controls. The attack can be executed remotely. The exploit is publicly avail...
CVE-2026-9580
- EPSS 0.29%
- Veröffentlicht 26.05.2026 20:15:14
- Zuletzt bearbeitet 27.05.2026 14:50:47
A vulnerability was determined in JeecgBoot up to 3.9.1. The affected element is the function LoginController.selectDepart of the file /sys/selectDepart. This manipulation causes improper access controls. Remote exploitation of the attack is possible...
CVE-2026-9579
- EPSS 0.21%
- Veröffentlicht 26.05.2026 19:45:09
- Zuletzt bearbeitet 27.05.2026 15:16:35
A vulnerability was found in JeecgBoot up to 3.9.1. Impacted is the function user.getUsername of the file /sys/user/login/setting/userEdit of the component SysUser. The manipulation of the argument userIdentity results in improper access controls. Th...
CVE-2026-9373
- EPSS 0.36%
- Veröffentlicht 24.05.2026 10:15:10
- Zuletzt bearbeitet 26.05.2026 19:37:00
A vulnerability has been found in JeecgBoot 3.9.1. This issue affects some unknown processing of the file /openapi/call/ of the component OpenAPI Endpoint. Such manipulation leads to improper authentication. The attack can be executed remotely. A hig...
CVE-2026-8195
- EPSS 0.27%
- Veröffentlicht 09.05.2026 20:16:30
- Zuletzt bearbeitet 11.05.2026 15:11:48
A vulnerability was detected in JeecgBoot up to 3.9.1. The affected element is an unknown function of the file jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/system/controller/CommonController.java of the component SVG File Hand...