Jeesite

Jeesite

20 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.38%
  • Veröffentlicht 30.04.2026 17:16:26
  • Zuletzt bearbeitet 30.04.2026 18:16:28

An issue in the fileMd5 parameter in the /a/file/upload endpoint of JeeSite v5.15.1 allows authenticated attackers with file upload permissions to execute a path traversal and write arbitrary files with whitelisted suffixes to arbitrary filesystem lo...

  • EPSS 0.44%
  • Veröffentlicht 30.04.2026 00:00:00
  • Zuletzt bearbeitet 04.05.2026 18:16:28

An issue in the fileEntityId parameter in the /a/file/upload endpoint of JeeSite v5.15.1 allows authenticated attackers with file upload permissions to execute a path traversal and write arbitrary files with whitelisted suffixes to arbitrary filesyst...

  • EPSS 0.16%
  • Veröffentlicht 30.04.2026 00:00:00
  • Zuletzt bearbeitet 30.04.2026 19:11:18

A stored cross-site scripting (XSS) vulnerability in the /msg/msgInner/save endpoint of JeeSite v5.15.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted input into the msgContent parameter.

Exploit
  • EPSS 0.58%
  • Veröffentlicht 02.03.2026 02:02:13
  • Zuletzt bearbeitet 29.04.2026 01:00:01

A vulnerability has been found in thinkgem JeeSite up to 5.15.1. The affected element is an unknown function of the component Connection Handler. The manipulation leads to path traversal. It is possible to initiate the attack remotely. The attack is ...

Exploit
  • EPSS 0.35%
  • Veröffentlicht 02.03.2026 01:32:10
  • Zuletzt bearbeitet 29.04.2026 01:00:01

A flaw has been found in thinkgem JeeSite up to 5.15.1. Impacted is an unknown function of the file /com/jeesite/common/shiro/cas/CasOutHandler.java of the component Endpoint. Executing a manipulation can lead to xml external entity reference. The at...

Exploit
  • EPSS 0.33%
  • Veröffentlicht 01.09.2025 21:32:08
  • Zuletzt bearbeitet 29.04.2026 01:00:01

A vulnerability was found in thinkgem JeeSite up to 5.12.1. This affects the function decodeUrl2 of the file common/src/main/java/com/jeesite/common/codec/EncodeUtils.java. The manipulation results in cross site scripting. It is possible to launch th...

Exploit
  • EPSS 0.3%
  • Veröffentlicht 20.07.2025 03:02:06
  • Zuletzt bearbeitet 29.04.2026 01:00:01

A vulnerability was found in thinkgem JeeSite up to 5.12.0. It has been declared as problematic. This vulnerability affects the function xssFilter of the file src/main/java/com/jeesite/common/codec/EncodeUtils.java of the component XSS Filter. The ma...

Exploit
  • EPSS 0.3%
  • Veröffentlicht 20.07.2025 02:44:05
  • Zuletzt bearbeitet 29.04.2026 01:00:01

A vulnerability was found in thinkgem JeeSite up to 5.12.0. It has been classified as critical. This affects the function Upload of the file src/main/java/com/jeesite/modules/file/web/FileUploadController.java. The manipulation leads to unrestricted ...

Exploit
  • EPSS 0.4%
  • Veröffentlicht 18.07.2025 11:44:07
  • Zuletzt bearbeitet 29.04.2026 01:00:01

A vulnerability classified as problematic was found in thinkgem JeeSite up to 5.12.0. This vulnerability affects the function sso of the file src/main/java/com/jeesite/modules/sys/web/SsoController.java. The manipulation of the argument redirect lead...

Exploit
  • EPSS 0.4%
  • Veröffentlicht 17.07.2025 22:14:07
  • Zuletzt bearbeitet 29.04.2026 01:00:01

A vulnerability, which was classified as problematic, was found in thinkgem JeeSite up to 5.12.0. Affected is the function select of the file src/main/java/com/jeesite/modules/cms/web/SiteController.java of the component Site Controller. The manipula...