Jeecg

Jeecgboot

52 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.49%
  • Veröffentlicht 19.12.2025 01:02:08
  • Zuletzt bearbeitet 29.04.2026 01:00:01

A weakness has been identified in JeecgBoot up to 3.9.0. The impacted element is the function SysUserOnlineController of the file jeecg-boot/jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/system/controller/SysUserOnlineControlle...

Exploit
  • EPSS 0.35%
  • Veröffentlicht 19.12.2025 00:32:08
  • Zuletzt bearbeitet 05.10.2026 18:10:00

A security flaw has been discovered in JeecgBoot up to 3.9.0. The affected element is an unknown function of the file jeecg-boot/jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/system/controller/SysTenantController.java of the co...

Exploit
  • EPSS 0.24%
  • Veröffentlicht 01.10.2025 20:18:39
  • Zuletzt bearbeitet 07.10.2025 14:42:52

Jeecgboot versions 3.8.2 and earlier are affected by a path traversal vulnerability. The endpoint is /sys/comment/addFile. This vulnerability allows attackers to upload files with system-whitelisted extensions to the system directory /opt, instead of...

Exploit
  • EPSS 0.24%
  • Veröffentlicht 01.10.2025 20:18:38
  • Zuletzt bearbeitet 07.10.2025 14:43:33

Jeecgboot versions 3.8.2 and earlier are affected by a path traversal vulnerability. This vulnerability allows attackers to upload files with system-whitelisted extensions to the system directory /opt, instead of the /opt/upFiles directory specified ...

Exploit
  • EPSS 0.4%
  • Veröffentlicht 19.09.2025 11:32:10
  • Zuletzt bearbeitet 29.04.2026 01:00:01

A weakness has been identified in JeecgBoot up to 3.8.2. Affected is an unknown function of the file /message/sysMessageTemplate/sendMsg. Executing manipulation can lead to improper authorization. The attack may be launched remotely. The exploit has ...

  • EPSS 0.32%
  • Veröffentlicht 12.09.2025 15:15:32
  • Zuletzt bearbeitet 29.04.2026 01:00:01

A security flaw has been discovered in JeecgBoot up to 3.8.2. Affected by this issue is some unknown functionality of the file /sys/tenant/exportLog of the component Tenant Log Export. The manipulation results in improper authorization. The attack ca...

Exploit
  • EPSS 0.43%
  • Veröffentlicht 12.09.2025 12:32:08
  • Zuletzt bearbeitet 29.04.2026 01:00:01

A vulnerability was identified in JeecgBoot up to 3.8.2. Affected by this vulnerability is an unknown functionality of the file /api/system/sendWebSocketMsg of the component WebSocket Message Handler. The manipulation of the argument userIds leads to...

Exploit
  • EPSS 0.24%
  • Veröffentlicht 22.08.2025 00:00:00
  • Zuletzt bearbeitet 01.10.2025 20:22:23

JeecgBoot versions from 3.4.3 up to 3.8.0 were found to contain a SQL injection vulnerability in the /jeecg-boot/online/cgreport/head/parseSql endpoint, which allows bypassing SQL blacklist restrictions.

Exploit
  • EPSS 0.72%
  • Veröffentlicht 11.05.2025 06:31:04
  • Zuletzt bearbeitet 31.12.2025 01:00:06

A vulnerability classified as problematic was found in JeecgBoot up to 3.8.0. This vulnerability affects the function unzipFile of the file /jeecg-boot/airag/knowledge/doc/import/zip of the component Document Library Upload. The manipulation of the a...

Exploit
  • EPSS 44.35%
  • Veröffentlicht 31.10.2024 01:15:14
  • Zuletzt bearbeitet 27.06.2025 19:45:28

JeecgBoot v3.7.1 was discovered to contain a SQL injection vulnerability via the component /onlDragDatasetHead/getTotalData.