CVE-2026-86228
- EPSS 0.23%
- Veröffentlicht 06.09.2026 22:30:10
- Zuletzt bearbeitet 08.09.2026 14:17:32
A security vulnerability has been detected in JeecgBoot up to 3.9.3. This vulnerability affects the function exportXls of the file jeecg-boot/jeecg-boot-module/jeecg-boot-module-airag/src/main/java/org/jeecg/modules/airag/llm/controller/AiragModelCon...
CVE-2026-78970
- EPSS 0.35%
- Veröffentlicht 04.09.2026 16:17:59
- Zuletzt bearbeitet 08.09.2026 19:42:20
JeecgBoot 3.9.2 and earlier contains an authorization bypass vulnerability in the SystemApiController component. An authenticated attacker with any valid JWT token can access multiple API endpoints (including queryAllUser, queryUsersByUsernames, quer...
CVE-2026-75411
- EPSS 0.22%
- Veröffentlicht 26.08.2026 00:00:00
- Zuletzt bearbeitet 01.09.2026 19:17:26
JeecgBoot v3.9.2 is vulnerable to Remote command execution. The CodeNode component of the AI Flow module supports Groovy script execution. While the `SecurityCheck` class employs a blacklist mechanism to intercept dangerous calls, the dynamic nature ...
CVE-2026-67925
- EPSS 0.21%
- Veröffentlicht 17.08.2026 00:00:00
- Zuletzt bearbeitet 31.08.2026 20:12:02
Cross Site Scripting vulnerability in JeecgBoot v.3.9.2 allows a remote attacker to execute arbitrary code via the endpoint /airag/chat/upload
CVE-2026-67926
- EPSS 0.21%
- Veröffentlicht 17.08.2026 00:00:00
- Zuletzt bearbeitet 31.08.2026 20:12:02
An issue in JeecgBoot v.3.9.2 allows a remote attacker to execute arbitrary code via the files Parameter in JeecgBoot AI Chat Module
CVE-2026-19000
- EPSS 0.29%
- Veröffentlicht 06.08.2026 05:15:08
- Zuletzt bearbeitet 12.08.2026 21:00:37
A vulnerability was identified in JeecgBoot up to 3.9.2. The affected element is an unknown function of the file /airag/chat/send of the component Anonymous Chat Attachment Parser. The manipulation leads to server-side request forgery. The attack can...
CVE-2026-58377
- EPSS 0.26%
- Veröffentlicht 30.06.2026 15:59:35
- Zuletzt bearbeitet 14.07.2026 22:17:29
JeecgBoot through 3.9.2 contains a broken access control vulnerability that allows authenticated low-privilege users to perform full create, read, update, and delete operations on OpenAPI credentials by accessing the OpenApiAuthController and OpenApi...
CVE-2026-11502
- EPSS 0.25%
- Veröffentlicht 08.06.2026 09:30:10
- Zuletzt bearbeitet 23.07.2026 07:10:00
A weakness has been identified in JeecgBoot up to 3.9.2. Impacted is the function HttpServletResponse.sendRedirect of the file jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/system/controller/ThirdLoginController.java of the com...
CVE-2026-11464
- EPSS 0.22%
- Veröffentlicht 07.06.2026 22:30:11
- Zuletzt bearbeitet 23.07.2026 07:10:00
A vulnerability was identified in JeecgBoot up to 3.9.2. Affected by this vulnerability is the function queryPageList of the file src\main\java\org\jeecg\modules\system\controller\SysUserController.java of the component User List Endpoint. The manipu...
CVE-2026-10240
- EPSS 0.27%
- Veröffentlicht 01.06.2026 09:16:15
- Zuletzt bearbeitet 22.07.2026 07:10:00
A vulnerability was identified in JeecgBoot up to 3.9.2. The impacted element is an unknown function of the file /airag/airagModel/test. The manipulation of the argument baseUrl leads to server-side request forgery. The attack is possible to be carri...