CVE-2026-5999
- EPSS 0.04%
- Veröffentlicht 10.04.2026 03:16:04
- Zuletzt bearbeitet 13.04.2026 15:02:06
A vulnerability has been found in JeecgBoot up to 3.9.1. This impacts an unknown function of the component SysAnnouncementController. Such manipulation leads to improper authorization. The attack can be launched remotely. The exploit has been disclos...
CVE-2026-5616
- EPSS 0.12%
- Veröffentlicht 06.04.2026 03:15:14
- Zuletzt bearbeitet 07.04.2026 13:20:35
A security vulnerability has been detected in JeecgBoot 3.9.0/3.9.1. The impacted element is an unknown function of the file jeecg-boot/jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/airag/JeecgBizToolsProvider.java of the compo...
CVE-2026-3672
- EPSS 0.03%
- Veröffentlicht 07.03.2026 21:32:13
- Zuletzt bearbeitet 09.03.2026 13:35:07
A vulnerability has been found in JeecgBoot up to 3.9.1. Affected is the function isExistSqlInjectKeyword of the file /jeecg-boot/sys/api/getDictItems. Such manipulation leads to sql injection. The attack may be performed from remote. The exploit has...
CVE-2026-2945
- EPSS 0.03%
- Veröffentlicht 22.02.2026 13:16:12
- Zuletzt bearbeitet 03.03.2026 00:24:46
A weakness has been identified in JeecgBoot 3.9.0. Affected by this vulnerability is an unknown functionality of the file /sys/common/uploadImgByHttp. Executing a manipulation of the argument fileUrl can lead to server-side request forgery. The attac...
CVE-2026-2822
- EPSS 0.01%
- Veröffentlicht 20.02.2026 04:32:10
- Zuletzt bearbeitet 24.02.2026 20:45:10
A security vulnerability has been detected in JeecgBoot up to 3.9.1. The affected element is an unknown function of the file /jeecgboot/sys/dict/loadDict/airag_app,1,create_by of the component Backend Interface. Such manipulation of the argument keyw...
CVE-2026-2555
- EPSS 0.05%
- Veröffentlicht 16.02.2026 12:16:22
- Zuletzt bearbeitet 18.02.2026 21:43:53
A weakness has been identified in JeecgBoot 3.9.1. This vulnerability affects the function importDocumentFromZip of the file org/jeecg/modules/airag/llm/controller/AiragKnowledgeController.java of the component Retrieval-Augmented Generation. Executi...
CVE-2026-2111
- EPSS 0.08%
- Veröffentlicht 07.02.2026 20:32:09
- Zuletzt bearbeitet 03.03.2026 00:20:04
A weakness has been identified in JeecgBoot up to 3.9.0. Affected by this issue is some unknown functionality of the file /airag/knowledge/doc/edit of the component Retrieval-Augmented Generation Module. Executing a manipulation of the argument fileP...
CVE-2026-1746
- EPSS 0.01%
- Veröffentlicht 02.02.2026 05:32:10
- Zuletzt bearbeitet 10.02.2026 17:43:15
A vulnerability was identified in JeecgBoot 3.9.0. This vulnerability affects unknown code of the file /JeecgBoot/sys/api/loadDictItemByKeyword of the component Online Report API. Such manipulation of the argument keyword leads to sql injection. The ...
CVE-2025-15126
- EPSS 0.04%
- Veröffentlicht 28.12.2025 07:32:06
- Zuletzt bearbeitet 30.12.2025 19:13:59
A weakness has been identified in JeecgBoot up to 3.9.0. Affected by this vulnerability is the function getPositionUserList of the file /sys/position/getPositionUserList. This manipulation of the argument positionId causes improper authorization. The...
CVE-2025-15125
- EPSS 0.04%
- Veröffentlicht 28.12.2025 07:15:53
- Zuletzt bearbeitet 30.12.2025 19:04:05
A security flaw has been discovered in JeecgBoot up to 3.9.0. Affected is the function queryDepartPermission of the file /sys/permission/queryDepartPermission. The manipulation of the argument departId results in improper authorization. The attack ca...