CVE-2026-67925
- EPSS 0.21%
- Veröffentlicht 17.08.2026 00:00:00
- Zuletzt bearbeitet 18.08.2026 16:18:15
Cross Site Scripting vulnerability in JeecgBoot v.3.9.2 allows a remote attacker to execute arbitrary code via the endpoint /airag/chat/upload
CVE-2026-67926
- EPSS 0.21%
- Veröffentlicht 17.08.2026 00:00:00
- Zuletzt bearbeitet 18.08.2026 16:18:15
An issue in JeecgBoot v.3.9.2 allows a remote attacker to execute arbitrary code via the files Parameter in JeecgBoot AI Chat Module
CVE-2026-19000
- EPSS 0.29%
- Veröffentlicht 06.08.2026 05:15:08
- Zuletzt bearbeitet 12.08.2026 21:00:37
A vulnerability was identified in JeecgBoot up to 3.9.2. The affected element is an unknown function of the file /airag/chat/send of the component Anonymous Chat Attachment Parser. The manipulation leads to server-side request forgery. The attack can...
CVE-2026-58377
- EPSS 0.26%
- Veröffentlicht 30.06.2026 15:59:35
- Zuletzt bearbeitet 14.07.2026 22:17:29
JeecgBoot through 3.9.2 contains a broken access control vulnerability that allows authenticated low-privilege users to perform full create, read, update, and delete operations on OpenAPI credentials by accessing the OpenApiAuthController and OpenApi...
CVE-2026-11502
- EPSS 0.25%
- Veröffentlicht 08.06.2026 09:30:10
- Zuletzt bearbeitet 23.07.2026 07:10:00
A weakness has been identified in JeecgBoot up to 3.9.2. Impacted is the function HttpServletResponse.sendRedirect of the file jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/system/controller/ThirdLoginController.java of the com...
CVE-2026-11464
- EPSS 0.22%
- Veröffentlicht 07.06.2026 22:30:11
- Zuletzt bearbeitet 23.07.2026 07:10:00
A vulnerability was identified in JeecgBoot up to 3.9.2. Affected by this vulnerability is the function queryPageList of the file src\main\java\org\jeecg\modules\system\controller\SysUserController.java of the component User List Endpoint. The manipu...
CVE-2026-10240
- EPSS 0.27%
- Veröffentlicht 01.06.2026 09:16:15
- Zuletzt bearbeitet 22.07.2026 07:10:00
A vulnerability was identified in JeecgBoot up to 3.9.2. The impacted element is an unknown function of the file /airag/airagModel/test. The manipulation of the argument baseUrl leads to server-side request forgery. The attack is possible to be carri...
CVE-2026-10239
- EPSS 0.27%
- Veröffentlicht 01.06.2026 09:16:15
- Zuletzt bearbeitet 22.07.2026 07:10:00
A vulnerability was determined in JeecgBoot up to 3.9.2. The affected element is the function WordUtil.addImage of the file /airag/word/edit. Executing a manipulation can lead to server-side request forgery. The attack can be executed remotely. The e...
CVE-2026-9604
- EPSS 0.22%
- Veröffentlicht 26.05.2026 22:15:15
- Zuletzt bearbeitet 24.07.2026 12:10:00
A vulnerability was detected in JeecgBoot up to 3.9.1. This vulnerability affects unknown code of the component AiragModelController. The manipulation of the argument list/queryById results in improper access controls. The attack can be executed remo...
CVE-2026-9581
- EPSS 0.21%
- Veröffentlicht 26.05.2026 20:30:13
- Zuletzt bearbeitet 24.07.2026 12:10:00
A vulnerability was identified in JeecgBoot up to 3.9.1. The impacted element is an unknown function of the file /sys/comment/add. Such manipulation leads to improper access controls. The attack can be executed remotely. The exploit is publicly avail...