VendorsHuayi-tecjeewmsall versions
Vulnerabilities

Huayi-tec Jeewms

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

19CVEs
CVE-2025-5385
JeeWMS cgformTemplateController.do doAdd path traversal
Published 2025-05-31 · Analyzed
9.8EPSS 0.005
CVE-2025-5388
JeeWMS generateController.do dogenerate sql injection
Published 2025-05-31 · Analyzed
9.8EPSS 0.003
CVE-2025-5387
JeeWMS File generateController.do dogenerate access control
Published 2025-05-31 · Analyzed
9.8EPSS 0.003
CVE-2025-5389
JeeWMS File generateController.do dogenerateOne2Many access control
Published 2025-05-31 · Analyzed
9.8EPSS 0.003
CVE-2025-5384
JeeWMS cgAutoListController.do CgAutoListController sql injection
Published 2025-05-31 · Analyzed
9.8EPSS 0.003
CVE-2025-5386
JeeWMS cgformTransController.do transEditor sql injection
Published 2025-05-31 · Analyzed
9.8EPSS 0.003
CVE-2025-5390
JeeWMS File filedeal.do filedeal access control
Published 2025-05-31 · Analyzed
9.8EPSS 0.003
CVE-2025-60269
JEEWMS 20250820 is vulnerable to SQL Injection in the exportXls function located in the src/main/java/org/jeecgframework/web/cgreport/controller/excel/CgExportExcelController.java file.
Published 2025-10-10 · Analyzed
9.4EPSS 0.003
CVE-2025-0392
Guangzhou Huayi Intelligent Technology Jeewms graphReportController.do datagridGraph sql injection
Published 2025-01-11 · Analyzed
8.8EPSS 0.006
CVE-2024-11251
erzhongxmu Jeewms AuthInterceptor cgReportController.do sql injection
Published 2024-11-15 · Analyzed
8.8EPSS 0.005
CVE-2025-0391
Guangzhou Huayi Intelligent Technology Jeewms CgFormBuildController. java saveOrUpdate sql injection
Published 2025-01-11 · Analyzed
8.8EPSS 0.005
CVE-2024-57761
An arbitrary file upload vulnerability in the parserXML() method of JeeWMS before v2025.01.01 allows attackers to execute arbitrary code via uploading a crafted file.
Published 2025-01-14 · Analyzed
8.1EPSS 0.005
CVE-2024-11961
Guangzhou Huayi Intelligent Technology Jeewms WmOmNoticeHController.java preHandle information disclosure
Published 2024-11-28 · Analyzed
7.5EPSS 0.009
CVE-2025-0390
Guangzhou Huayi Intelligent Technology Jeewms wmOmNoticeHController.do path traversal
Published 2025-01-11 · Analyzed
7.5EPSS 0.008
CVE-2024-12347
Guangzhou Huayi Intelligent Technology Jeewms Druid Monitoring Interface index.html improper authorization
Published 2024-12-08 · Analyzed
6.9EPSS 0.006
CVE-2025-60268
An arbitrary file upload vulnerability exists in JeeWMS 20250820, which is caused by the lack of file checking in the saveFiles function in /jeewms/cgUploadController.do. An attacker with normal privileges was able to upload a malicious file that would lead to remote code execution.
Published 2025-10-10 · Analyzed
6.5EPSS 0.004
CVE-2025-70311
JEEWMS 1.0 is vulnerable to SQL Injection. Attackers can inject malicious SQL statements through the id1 and id2 parameters in the /systemControl.do interface for attack.
Published 2026-02-03 · Analyzed
6.5EPSS 0.002
CVE-2026-3028
erzhongxmu JEEWMS JeecgListDemoController.java doAdd cross site scripting
Published 2026-02-23 · Analyzed
6.1EPSS 0.005
CVE-2025-55834
A Cross Site Scripting vulnerability in JeeWMS v.3.7 and before allows a remote attacker to obtain sensitive information via the logController.do component
Published 2025-09-16 · Analyzed
6.1EPSS 0.003