CVE-2026-9580
- EPSS 0.29%
- Veröffentlicht 26.05.2026 20:15:14
- Zuletzt bearbeitet 24.07.2026 12:10:00
A vulnerability was determined in JeecgBoot up to 3.9.1. The affected element is the function LoginController.selectDepart of the file /sys/selectDepart. This manipulation causes improper access controls. Remote exploitation of the attack is possible...
CVE-2026-9579
- EPSS 0.21%
- Veröffentlicht 26.05.2026 19:45:09
- Zuletzt bearbeitet 24.07.2026 12:10:00
A vulnerability was found in JeecgBoot up to 3.9.1. Impacted is the function user.getUsername of the file /sys/user/login/setting/userEdit of the component SysUser. The manipulation of the argument userIdentity results in improper access controls. Th...
CVE-2026-9373
- EPSS 0.36%
- Veröffentlicht 24.05.2026 10:15:10
- Zuletzt bearbeitet 23.07.2026 11:10:00
A vulnerability has been found in JeecgBoot 3.9.1. This issue affects some unknown processing of the file /openapi/call/ of the component OpenAPI Endpoint. Such manipulation leads to improper authentication. The attack can be executed remotely. A hig...
- EPSS 0.27%
- Veröffentlicht 09.05.2026 20:16:30
- Zuletzt bearbeitet 24.07.2026 08:10:00
A vulnerability was detected in JeecgBoot up to 3.9.1. The affected element is an unknown function of the file jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/system/controller/CommonController.java of the component SVG File Hand...
CVE-2026-8196
- EPSS 0.46%
- Veröffentlicht 09.05.2026 20:15:11
- Zuletzt bearbeitet 24.07.2026 08:10:00
A flaw has been found in JeecgBoot 3.9.1. The impacted element is an unknown function of the file jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/system/controller/LoginController.java of the component mLogin Endpoint. This manip...
CVE-2026-8114
- EPSS 0.2%
- Veröffentlicht 07.05.2026 22:00:11
- Zuletzt bearbeitet 08.05.2026 15:47:03
A vulnerability was identified in JeecgBoot up to 3.9.1. Affected by this issue is some unknown functionality of the file /sys/dict/loadTreeData of the component JSON Object Handler. The manipulation of the argument condition leads to sql injection. ...
CVE-2026-7605
- EPSS 0.21%
- Veröffentlicht 02.05.2026 06:15:12
- Zuletzt bearbeitet 05.05.2026 19:15:59
A security flaw has been discovered in JeecgBoot up to 3.9.1. This vulnerability affects the function CommonController.uploadImgByHttp/HttpFileToMultipartFileUtil.httpFileToMultipartFile/HttpFileToMultipartFileUtil.downloadImageData of the file Commo...
CVE-2026-7604
- EPSS 0.21%
- Veröffentlicht 02.05.2026 05:16:01
- Zuletzt bearbeitet 05.05.2026 19:17:22
A vulnerability was identified in JeecgBoot up to 3.9.1. This affects the function OpenApiController.add/OpenApiController.call of the file OpenApiController.java of the component OpenApi Service. Such manipulation of the argument originUrl database ...
CVE-2026-7603
- EPSS 0.27%
- Veröffentlicht 02.05.2026 05:16:01
- Zuletzt bearbeitet 05.05.2026 20:16:40
A vulnerability was determined in JeecgBoot up to 3.9.1. Affected by this issue is the function checkPathTraversalBatch of the file FileDownloadUtils.jav of the component LoadFile Endpoint. This manipulation of the argument files causes server-side r...
CVE-2026-7602
- EPSS 0.21%
- Veröffentlicht 02.05.2026 03:15:12
- Zuletzt bearbeitet 05.05.2026 19:17:22
A vulnerability was found in JeecgBoot up to 3.9.1. Affected by this vulnerability is an unknown functionality of the file /sys/fillRule/edit of the component FillRuleUtil Component. The manipulation of the argument ruleClass results in improper auth...