Home/Product/jeecg boot
Product

jeecg boot

61 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2024-43028
>= 3.0 and <= 3.5.3
A command injection vulnerability in the component /jmreport/show of jeecg boot v3.0.0 to v3.5.3 allows attackers to execute arbit
9.8CRITICAL
CVE-2024-40489
>= 3.0 and <= 3.5.3
There is an injection vulnerability in jeecg boot versions 3.0.0 to 3.5.3 due to lax character filtering, which allows attackers t
9.8CRITICAL
CVE-2026-2945
all versions
A weakness has been identified in JeecgBoot 3.9.0. Affected by this vulnerability is an unknown functionality of the file /sys/com
6.3MEDIUM
CVE-2026-2822
<= 3.9.1
A security vulnerability has been detected in JeecgBoot up to 3.9.1. The affected element is an unknown function of the file /jeec
6.3MEDIUM
CVE-2026-2555
all versions
A weakness has been identified in JeecgBoot 3.9.1. This vulnerability affects the function importDocumentFromZip of the file org/j
5.0MEDIUM
CVE-2026-2111
<= 3.9.0
A weakness has been identified in JeecgBoot up to 3.9.0. Affected by this issue is some unknown functionality of the file /airag/k
4.3MEDIUM
CVE-2026-1746
all versions
A vulnerability was identified in JeecgBoot 3.9.0. This vulnerability affects unknown code of the file /JeecgBoot/sys/api/loadDict
6.3MEDIUM
CVE-2025-15126
<= 3.9.0
A weakness has been identified in JeecgBoot up to 3.9.0. Affected by this vulnerability is the function getPositionUserList of the
3.1LOW
CVE-2025-15125
<= 3.9.0
A security flaw has been discovered in JeecgBoot up to 3.9.0. Affected is the function queryDepartPermission of the file /sys/perm
3.1LOW
CVE-2025-15124
<= 3.9.0
A vulnerability was identified in JeecgBoot up to 3.9.0. This impacts the function getParameterMap of the file /sys/sysDepartPermi
3.1LOW
CVE-2025-15123
<= 3.9.0
A vulnerability was determined in JeecgBoot up to 3.9.0. This affects an unknown function of the file /sys/sysDepartPermission/dat
3.1LOW
CVE-2025-15122
<= 3.9.0
A vulnerability was found in JeecgBoot up to 3.9.0. The impacted element is the function loadDatarule of the file /sys/sysDepartRo
3.1LOW
CVE-2025-15121
<= 3.9.0
A vulnerability has been found in JeecgBoot up to 3.9.0. The affected element is the function getDeptRoleByUserId of the file /sys
2.4LOW
CVE-2025-15120
<= 3.9.0
A flaw has been found in JeecgBoot up to 3.9.0. Impacted is the function getDeptRoleList of the file /sys/sysDepartRole/getDeptRol
3.1LOW
CVE-2025-15119
<= 3.9.0
A vulnerability was detected in JeecgBoot up to 3.9.0. This issue affects the function queryPageList of the file /sys/sysDepartRol
3.1LOW
CVE-2025-14909
<= 3.9.0
A weakness has been identified in JeecgBoot up to 3.9.0. The impacted element is the function SysUserOnlineController of the file
4.3MEDIUM
CVE-2025-14908
<= 3.9.0
A security flaw has been discovered in JeecgBoot up to 3.9.0. The affected element is an unknown function of the file jeecg-boot/j
6.3MEDIUM
CVE-2025-61189
<= 3.8.2
Jeecgboot versions 3.8.2 and earlier are affected by a path traversal vulnerability. The endpoint is /sys/comment/addFile. This vu
6.3MEDIUM
CVE-2025-61188
<= 3.8.2
Jeecgboot versions 3.8.2 and earlier are affected by a path traversal vulnerability. This vulnerability allows attackers to upload
6.3MEDIUM
CVE-2025-10981
<= 3.8.2
A vulnerability was detected in JeecgBoot up to 3.8.2. This impacts an unknown function of the file /sys/tenant/exportXls. Perform
4.3MEDIUM
CVE-2025-10980
<= 3.8.2
A security vulnerability has been detected in JeecgBoot up to 3.8.2. This affects an unknown function of the file /sys/position/ex
4.3MEDIUM
CVE-2025-10979
<= 3.8.2
A weakness has been identified in JeecgBoot up to 3.8.2. The impacted element is an unknown function of the file /sys/role/exportX
4.3MEDIUM
CVE-2025-10978
<= 3.8.2
A security flaw has been discovered in JeecgBoot up to 3.8.2. The affected element is an unknown function of the file /sys/user/ex
4.3MEDIUM
CVE-2025-10977
<= 3.8.2
A vulnerability was identified in JeecgBoot up to 3.8.2. Impacted is an unknown function of the file /sys/tenant/deleteBatch. The
3.1LOW
CVE-2025-10976
<= 3.8.2
A vulnerability was determined in JeecgBoot up to 3.8.2. This issue affects some unknown processing of the file /api/getDepartUser
3.1LOW
CVE-2025-10707
<= 3.8.2
A weakness has been identified in JeecgBoot up to 3.8.2. Affected is an unknown function of the file /message/sysMessageTemplate/s
6.3MEDIUM
CVE-2025-10319
<= 3.8.2
A security flaw has been discovered in JeecgBoot up to 3.8.2. Affected by this issue is some unknown functionality of the file /sy
4.3MEDIUM
CVE-2025-10318
<= 3.8.2
A vulnerability was identified in JeecgBoot up to 3.8.2. Affected by this vulnerability is an unknown functionality of the file /a
6.3MEDIUM
CVE-2025-51825
>= 3.4.3 and <= 3.8.0
JeecgBoot versions from 3.4.3 up to 3.8.0 were found to contain a SQL injection vulnerability in the /jeecg-boot/online/cgreport/h
6.5MEDIUM
CVE-2025-4533
<= 3.8.0
A vulnerability classified as problematic was found in JeecgBoot up to 3.8.0. This vulnerability affects the function unzipFile of
2.7LOW
CVE-2024-57606
all versions
SQL injection vulnerability in Beijing Guoju Information Technology Co., Ltd JeecgBoot v.3.7.2 allows a remote attacker to obtain
7.5HIGH
CVE-2024-48307
all versions
JeecgBoot v3.7.1 was discovered to contain a SQL injection vulnerability via the component /onlDragDatasetHead/getTotalData.
9.8CRITICAL
CVE-2023-41544
<= 3.5.3
SSTI injection vulnerability in jeecg-boot version 3.5.3, allows remote attackers to execute arbitrary code via crafted HTTP reque
9.8CRITICAL
CVE-2023-41543
<= 3.5.3
SQL injection vulnerability in jeecg-boot v3.5.3, allows remote attackers to escalate privileges and obtain sensitive information
9.8CRITICAL
CVE-2023-41542
<= 3.5.3
SQL injection vulnerability in jeecg-boot version 3.5.3, allows remote attackers to escalate privileges and obtain sensitive infor
9.8CRITICAL
CVE-2023-47467
all versions
Directory Traversal vulnerability in jeecg-boot v.3.6.0 allows a remote privileged attacker to obtain sensitive information via th
6.5MEDIUM
CVE-2023-40989
all versions
SQL injection vulnerbility in jeecgboot jeecg-boot v 3.0, 3.5.3 that allows a remote attacker to execute arbitrary code via a craf
9.8CRITICAL
CVE-2023-42268
<= 3.5.3
Jeecg boot up to v3.5.3 was discovered to contain a SQL injection vulnerability via the component /jeecg-boot/jmreport/show.
9.8CRITICAL
CVE-2023-41578
<= 3.5.3
Jeecg boot up to v3.5.3 was discovered to contain an arbitrary file read vulnerability via the interface /testConnection.
7.5HIGH
CVE-2023-38905
<= 3.5.0
SQL injection vulnerability in Jeecg-boot v.3.5.0 and before allows a local attacker to cause a denial of service via the Benchmar
5.5MEDIUM
CVE-2023-38992
all versions
jeecg-boot v3.5.1 was discovered to contain a SQL injection vulnerability via the title parameter at /sys/dict/loadTreeData.
9.8CRITICAL
CVE-2023-34603
<= 3.5.1
JeecgBoot up to v 3.5.1 was discovered to contain a SQL injection vulnerability via the component queryFilterTableDictInfo at org.
7.5HIGH
CVE-2023-34602
<= 3.5.1
JeecgBoot up to v 3.5.1 was discovered to contain a SQL injection vulnerability via the component queryTableDictItemsByCode at org
7.5HIGH
CVE-2023-34660
all versions
jjeecg-boot V3.5.0 has an unauthorized arbitrary file upload in /jeecg-boot/jmreport/upload interface.
6.5MEDIUM
CVE-2023-34659
all versions
jeecg-boot 3.5.0 and 3.5.1 have a SQL injection vulnerability the id parameter of the /jeecg-boot/jmreport/show interface.
9.8CRITICAL
CVE-2023-1784
all versions
A vulnerability was found in jeecg-boot 3.5.0 and classified as critical. This issue affects some unknown processing of the compon
5.3MEDIUM
CVE-2023-1741
all versions
A vulnerability was found in jeecg-boot 3.5.0. It has been declared as problematic. Affected by this vulnerability is an unknown f
4.3MEDIUM
CVE-2023-1454
all versions
A vulnerability classified as critical has been found in jeecg-boot 3.5.0. This affects an unknown part of the file jmreport/qures
6.3MEDIUM
CVE-2022-47105
all versions
Jeecg-boot v3.4.4 was discovered to contain a SQL injection vulnerability via the component /sys/dict/queryTableData.
9.8CRITICAL
CVE-2022-45210
all versions
Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/user/deleteRecycleBin.
4.3MEDIUM
CVE-2022-45208
all versions
Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/user/putRecycleBin.
4.3MEDIUM
CVE-2022-45207
all versions
Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component updateNullByEmptyString.
9.8CRITICAL
CVE-2022-45206
all versions
Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/duplicate/check.
9.8CRITICAL
CVE-2022-45205
all versions
Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/dict/queryTableData.
5.3MEDIUM
CVE-2022-2647
all versions
A vulnerability was found in jeecg-boot. It has been declared as critical. This vulnerability affects unknown code of the file /ap
7.3HIGH
CVE-2021-44585
all versions
A Cross Site Scripting (XSS) vulnerabilitiy exits in jeecg-boot 3.0 in /jeecg-boot/jmreport/view with a mouseover event.
6.1MEDIUM
CVE-2022-22881
<= 3.0
Jeecg-boot v3.0 was discovered to contain a SQL injection vulnerability via the code parameter in /sys/user/queryUserComponentData
9.8CRITICAL
CVE-2022-22880
<= 3.0
Jeecg-boot v3.0 was discovered to contain a SQL injection vulnerability via the code parameter in /jeecg-boot/sys/user/queryUserBy
9.8CRITICAL
CVE-2021-46089
all versions
In JeecgBoot 3.0, there is a SQL injection vulnerability that can operate the database with root privileges.
9.8CRITICAL
CVE-2020-28088
all versions
An arbitrary file upload vulnerability in /jeecg-boot/sys/common/upload of jeecg-boot CMS 2.3 allows attackers to execute arbitrar
9.8CRITICAL
CVE-2020-28087
all versions
A SQL injection vulnerability in /jeecg boot/sys/dict/loadtreedata of jeecg-boot CMS 2.3 allows attackers to access sensitive data
7.5HIGH
threatengine.sh