CVE-2026-10239
- EPSS 0.27%
- Veröffentlicht 01.06.2026 09:16:15
- Zuletzt bearbeitet 22.07.2026 07:10:00
A vulnerability was determined in JeecgBoot up to 3.9.2. The affected element is the function WordUtil.addImage of the file /airag/word/edit. Executing a manipulation can lead to server-side request forgery. The attack can be executed remotely. The e...
CVE-2026-9604
- EPSS 0.22%
- Veröffentlicht 26.05.2026 22:15:15
- Zuletzt bearbeitet 24.07.2026 12:10:00
A vulnerability was detected in JeecgBoot up to 3.9.1. This vulnerability affects unknown code of the component AiragModelController. The manipulation of the argument list/queryById results in improper access controls. The attack can be executed remo...
CVE-2026-9581
- EPSS 0.21%
- Veröffentlicht 26.05.2026 20:30:13
- Zuletzt bearbeitet 24.07.2026 12:10:00
A vulnerability was identified in JeecgBoot up to 3.9.1. The impacted element is an unknown function of the file /sys/comment/add. Such manipulation leads to improper access controls. The attack can be executed remotely. The exploit is publicly avail...
CVE-2026-9580
- EPSS 0.29%
- Veröffentlicht 26.05.2026 20:15:14
- Zuletzt bearbeitet 24.07.2026 12:10:00
A vulnerability was determined in JeecgBoot up to 3.9.1. The affected element is the function LoginController.selectDepart of the file /sys/selectDepart. This manipulation causes improper access controls. Remote exploitation of the attack is possible...
CVE-2026-9579
- EPSS 0.21%
- Veröffentlicht 26.05.2026 19:45:09
- Zuletzt bearbeitet 24.07.2026 12:10:00
A vulnerability was found in JeecgBoot up to 3.9.1. Impacted is the function user.getUsername of the file /sys/user/login/setting/userEdit of the component SysUser. The manipulation of the argument userIdentity results in improper access controls. Th...
CVE-2026-9373
- EPSS 0.36%
- Veröffentlicht 24.05.2026 10:15:10
- Zuletzt bearbeitet 23.07.2026 11:10:00
A vulnerability has been found in JeecgBoot 3.9.1. This issue affects some unknown processing of the file /openapi/call/ of the component OpenAPI Endpoint. Such manipulation leads to improper authentication. The attack can be executed remotely. A hig...
- EPSS 0.27%
- Veröffentlicht 09.05.2026 20:16:30
- Zuletzt bearbeitet 24.07.2026 08:10:00
A vulnerability was detected in JeecgBoot up to 3.9.1. The affected element is an unknown function of the file jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/system/controller/CommonController.java of the component SVG File Hand...
CVE-2026-8196
- EPSS 0.46%
- Veröffentlicht 09.05.2026 20:15:11
- Zuletzt bearbeitet 24.07.2026 08:10:00
A flaw has been found in JeecgBoot 3.9.1. The impacted element is an unknown function of the file jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/system/controller/LoginController.java of the component mLogin Endpoint. This manip...
CVE-2026-8114
- EPSS 0.2%
- Veröffentlicht 07.05.2026 22:00:11
- Zuletzt bearbeitet 08.05.2026 15:47:03
A vulnerability was identified in JeecgBoot up to 3.9.1. Affected by this issue is some unknown functionality of the file /sys/dict/loadTreeData of the component JSON Object Handler. The manipulation of the argument condition leads to sql injection. ...
CVE-2026-7605
- EPSS 0.21%
- Veröffentlicht 02.05.2026 06:15:12
- Zuletzt bearbeitet 05.05.2026 19:15:59
A security flaw has been discovered in JeecgBoot up to 3.9.1. This vulnerability affects the function CommonController.uploadImgByHttp/HttpFileToMultipartFileUtil.httpFileToMultipartFile/HttpFileToMultipartFileUtil.downloadImageData of the file Commo...