CVE-2026-2111
- EPSS 0.52%
- Veröffentlicht 07.02.2026 20:32:09
- Zuletzt bearbeitet 29.04.2026 01:00:01
A weakness has been identified in JeecgBoot up to 3.9.0. Affected by this issue is some unknown functionality of the file /airag/knowledge/doc/edit of the component Retrieval-Augmented Generation Module. Executing a manipulation of the argument fileP...
CVE-2026-1746
- EPSS 0.44%
- Veröffentlicht 02.02.2026 05:32:10
- Zuletzt bearbeitet 29.04.2026 01:00:01
A vulnerability was identified in JeecgBoot 3.9.0. This vulnerability affects unknown code of the file /JeecgBoot/sys/api/loadDictItemByKeyword of the component Online Report API. Such manipulation of the argument keyword leads to sql injection. The ...
CVE-2025-15126
- EPSS 0.35%
- Veröffentlicht 28.12.2025 07:32:06
- Zuletzt bearbeitet 29.04.2026 01:00:01
A weakness has been identified in JeecgBoot up to 3.9.0. Affected by this vulnerability is the function getPositionUserList of the file /sys/position/getPositionUserList. This manipulation of the argument positionId causes improper authorization. The...
CVE-2025-15125
- EPSS 0.28%
- Veröffentlicht 28.12.2025 07:15:53
- Zuletzt bearbeitet 29.04.2026 01:00:01
A security flaw has been discovered in JeecgBoot up to 3.9.0. Affected is the function queryDepartPermission of the file /sys/permission/queryDepartPermission. The manipulation of the argument departId results in improper authorization. The attack ca...
CVE-2025-15124
- EPSS 0.28%
- Veröffentlicht 28.12.2025 06:32:06
- Zuletzt bearbeitet 29.04.2026 01:00:01
A vulnerability was identified in JeecgBoot up to 3.9.0. This impacts the function getParameterMap of the file /sys/sysDepartPermission/list. The manipulation of the argument departId leads to improper authorization. The attack can be initiated remot...
CVE-2025-15123
- EPSS 0.28%
- Veröffentlicht 28.12.2025 06:02:05
- Zuletzt bearbeitet 29.04.2026 01:00:01
A vulnerability was determined in JeecgBoot up to 3.9.0. This affects an unknown function of the file /sys/sysDepartPermission/datarule/. Executing manipulation can lead to improper authorization. It is possible to launch the attack remotely. The att...
CVE-2025-15122
- EPSS 0.28%
- Veröffentlicht 28.12.2025 05:16:05
- Zuletzt bearbeitet 29.04.2026 01:00:01
A vulnerability was found in JeecgBoot up to 3.9.0. The impacted element is the function loadDatarule of the file /sys/sysDepartRole/datarule/. Performing manipulation of the argument departId/roleId results in improper authorization. It is possible ...
CVE-2025-15121
- EPSS 0.43%
- Veröffentlicht 28.12.2025 04:32:06
- Zuletzt bearbeitet 30.12.2025 19:06:19
A vulnerability has been found in JeecgBoot up to 3.9.0. The affected element is the function getDeptRoleByUserId of the file /sys/sysDepartRole/getDeptRoleByUserId. Such manipulation of the argument departId leads to information disclosure. The vend...
CVE-2025-15120
- EPSS 0.29%
- Veröffentlicht 28.12.2025 04:02:06
- Zuletzt bearbeitet 29.04.2026 01:00:01
A flaw has been found in JeecgBoot up to 3.9.0. Impacted is the function getDeptRoleList of the file /sys/sysDepartRole/getDeptRoleList. This manipulation of the argument departId causes improper authorization. The attack is possible to be carried ou...
CVE-2025-15119
- EPSS 0.25%
- Veröffentlicht 28.12.2025 03:32:06
- Zuletzt bearbeitet 29.04.2026 01:00:01
A vulnerability was detected in JeecgBoot up to 3.9.0. This issue affects the function queryPageList of the file /sys/sysDepartRole/list. The manipulation of the argument deptId results in improper authorization. The attack can be executed remotely. ...