Jeecg

Jeecgboot

52 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.23%
  • Veröffentlicht 06.09.2026 22:30:10
  • Zuletzt bearbeitet 08.09.2026 14:17:32

A security vulnerability has been detected in JeecgBoot up to 3.9.3. This vulnerability affects the function exportXls of the file jeecg-boot/jeecg-boot-module/jeecg-boot-module-airag/src/main/java/org/jeecg/modules/airag/llm/controller/AiragModelCon...

  • EPSS 0.35%
  • Veröffentlicht 04.09.2026 16:17:59
  • Zuletzt bearbeitet 08.09.2026 19:42:20

JeecgBoot 3.9.2 and earlier contains an authorization bypass vulnerability in the SystemApiController component. An authenticated attacker with any valid JWT token can access multiple API endpoints (including queryAllUser, queryUsersByUsernames, quer...

  • EPSS 0.22%
  • Veröffentlicht 26.08.2026 00:00:00
  • Zuletzt bearbeitet 01.09.2026 19:17:26

JeecgBoot v3.9.2 is vulnerable to Remote command execution. The CodeNode component of the AI Flow module supports Groovy script execution. While the `SecurityCheck` class employs a blacklist mechanism to intercept dangerous calls, the dynamic nature ...

  • EPSS 0.21%
  • Veröffentlicht 17.08.2026 00:00:00
  • Zuletzt bearbeitet 31.08.2026 20:12:02

Cross Site Scripting vulnerability in JeecgBoot v.3.9.2 allows a remote attacker to execute arbitrary code via the endpoint /airag/chat/upload

  • EPSS 0.21%
  • Veröffentlicht 17.08.2026 00:00:00
  • Zuletzt bearbeitet 31.08.2026 20:12:02

An issue in JeecgBoot v.3.9.2 allows a remote attacker to execute arbitrary code via the files Parameter in JeecgBoot AI Chat Module

Exploit
  • EPSS 0.29%
  • Veröffentlicht 06.08.2026 05:15:08
  • Zuletzt bearbeitet 12.08.2026 21:00:37

A vulnerability was identified in JeecgBoot up to 3.9.2. The affected element is an unknown function of the file /airag/chat/send of the component Anonymous Chat Attachment Parser. The manipulation leads to server-side request forgery. The attack can...

Exploit
  • EPSS 0.26%
  • Veröffentlicht 30.06.2026 15:59:35
  • Zuletzt bearbeitet 14.07.2026 22:17:29

JeecgBoot through 3.9.2 contains a broken access control vulnerability that allows authenticated low-privilege users to perform full create, read, update, and delete operations on OpenAPI credentials by accessing the OpenApiAuthController and OpenApi...

Exploit
  • EPSS 0.25%
  • Veröffentlicht 08.06.2026 09:30:10
  • Zuletzt bearbeitet 23.07.2026 07:10:00

A weakness has been identified in JeecgBoot up to 3.9.2. Impacted is the function HttpServletResponse.sendRedirect of the file jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/system/controller/ThirdLoginController.java of the com...

Exploit
  • EPSS 0.22%
  • Veröffentlicht 07.06.2026 22:30:11
  • Zuletzt bearbeitet 23.07.2026 07:10:00

A vulnerability was identified in JeecgBoot up to 3.9.2. Affected by this vulnerability is the function queryPageList of the file src\main\java\org\jeecg\modules\system\controller\SysUserController.java of the component User List Endpoint. The manipu...

  • EPSS 0.27%
  • Veröffentlicht 01.06.2026 09:16:15
  • Zuletzt bearbeitet 22.07.2026 07:10:00

A vulnerability was identified in JeecgBoot up to 3.9.2. The impacted element is an unknown function of the file /airag/airagModel/test. The manipulation of the argument baseUrl leads to server-side request forgery. The attack is possible to be carri...