Home/Product/jeesite
Product

jeesite

19 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-3405
<= 5.15.1
A vulnerability has been found in thinkgem JeeSite up to 5.15.1. The affected element is an unknown function of the component Conn
3.1LOW
CVE-2026-3404
<= 5.15.1
A flaw has been found in thinkgem JeeSite up to 5.15.1. Impacted is an unknown function of the file /com/jeesite/common/shiro/cas/
5.0MEDIUM
CVE-2025-9796
< 5.13.0
A vulnerability was found in thinkgem JeeSite up to 5.12.1. This affects the function decodeUrl2 of the file common/src/main/java/
3.5LOW
CVE-2025-7865
<= 5.12.0
A vulnerability was found in thinkgem JeeSite up to 5.12.0. It has been declared as problematic. This vulnerability affects the fu
3.5LOW
CVE-2025-7864
< 5.12.1
A vulnerability was found in thinkgem JeeSite up to 5.12.0. It has been classified as critical. This affects the function Upload o
6.3MEDIUM
CVE-2025-7863
< 5.12.1
A vulnerability was found in thinkgem JeeSite up to 5.12.0 and classified as problematic. Affected by this issue is the function r
3.5LOW
CVE-2025-7785
< 5.12.1
A vulnerability classified as problematic was found in thinkgem JeeSite up to 5.12.0. This vulnerability affects the function sso
4.3MEDIUM
CVE-2025-7763
< 5.12.1
A vulnerability, which was classified as problematic, was found in thinkgem JeeSite up to 5.12.0. Affected is the function select
4.3MEDIUM
CVE-2025-7759
< 5.12.1
A vulnerability was identified in thinkgem JeeSite up to 5.12.0. This vulnerability affects unknown code of the file modules/core/
6.3MEDIUM
CVE-2025-5186
<= 5.11.1
A vulnerability was found in thinkgem JeeSite up to 5.11.1. It has been rated as critical. Affected by this issue is the function
6.3MEDIUM
CVE-2024-8112
all versions
A vulnerability was found in thinkgem JeeSite 5.3. It has been rated as problematic. This issue affects some unknown processing of
4.3MEDIUM
CVE-2023-38991
all versions
An issue in the delete function in the ActModelController class of jeesite v1.2.6 allows authenticated attackers to arbitrarily de
5.4MEDIUM
CVE-2023-38990
all versions
An issue in the delete function in the MenuController class of jeesite v1.2.6 allows authenticated attackers to arbitrarily delete
4.3MEDIUM
CVE-2023-38989
all versions
An issue in the delete function in the UserController class of jeesite v1.2.6 allows authenticated attackers to arbitrarily delete
4.3MEDIUM
CVE-2023-38988
all versions
An issue in the delete function in the OaNotifyController class of jeesite v1.2.6 allows authenticated attackers to arbitrarily de
4.3MEDIUM
CVE-2023-34601
< 2023-05-27
Jeesite before commit 10742d3 was discovered to contain a SQL injection vulnerability via the component ${businessTable} at /act/A
9.8CRITICAL
CVE-2020-19229
all versions
Jeesite 1.2.7 uses the apache shiro version 1.2.3 affected by CVE-2016-4437. Because of this version of the java deserialization v
9.8CRITICAL
CVE-2019-1010201
all versions
Jeesite 1.2.7 is affected by: SQL Injection. The impact is: sensitive information disclosure. The component is: updateProcInsIdByB
6.5MEDIUM
CVE-2019-1010202
all versions
Jeesite 1.2.7 is affected by: XML External Entity (XXE). The impact is: sensitive information disclosure. The component is: conver
6.5MEDIUM
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin