VendorsHuayi-tecjeewmsany version
Vulnerabilities

Huayi-tec Jeewms any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

16CVEs
CVE-2025-5385
JeeWMS cgformTemplateController.do doAdd path traversal
Published 2025-05-31 · Analyzed
9.8EPSS 0.005
CVE-2025-5388
JeeWMS generateController.do dogenerate sql injection
Published 2025-05-31 · Analyzed
9.8EPSS 0.003
CVE-2025-5387
JeeWMS File generateController.do dogenerate access control
Published 2025-05-31 · Analyzed
9.8EPSS 0.003
CVE-2025-5389
JeeWMS File generateController.do dogenerateOne2Many access control
Published 2025-05-31 · Analyzed
9.8EPSS 0.003
CVE-2025-5384
JeeWMS cgAutoListController.do CgAutoListController sql injection
Published 2025-05-31 · Analyzed
9.8EPSS 0.003
CVE-2025-5386
JeeWMS cgformTransController.do transEditor sql injection
Published 2025-05-31 · Analyzed
9.8EPSS 0.003
CVE-2025-5390
JeeWMS File filedeal.do filedeal access control
Published 2025-05-31 · Analyzed
9.8EPSS 0.003
CVE-2025-0392
Guangzhou Huayi Intelligent Technology Jeewms graphReportController.do datagridGraph sql injection
Published 2025-01-11 · Analyzed
8.8EPSS 0.006
CVE-2024-11251
erzhongxmu Jeewms AuthInterceptor cgReportController.do sql injection
Published 2024-11-15 · Analyzed
8.8EPSS 0.005
CVE-2025-0391
Guangzhou Huayi Intelligent Technology Jeewms CgFormBuildController. java saveOrUpdate sql injection
Published 2025-01-11 · Analyzed
8.8EPSS 0.005
CVE-2024-57761
An arbitrary file upload vulnerability in the parserXML() method of JeeWMS before v2025.01.01 allows attackers to execute arbitrary code via uploading a crafted file.
Published 2025-01-14 · Analyzed
8.1EPSS 0.005
CVE-2025-0390
Guangzhou Huayi Intelligent Technology Jeewms wmOmNoticeHController.do path traversal
Published 2025-01-11 · Analyzed
7.5EPSS 0.008
CVE-2024-12347
Guangzhou Huayi Intelligent Technology Jeewms Druid Monitoring Interface index.html improper authorization
Published 2024-12-08 · Analyzed
6.9EPSS 0.006
CVE-2025-70311
JEEWMS 1.0 is vulnerable to SQL Injection. Attackers can inject malicious SQL statements through the id1 and id2 parameters in the /systemControl.do interface for attack.
Published 2026-02-03 · Analyzed
6.5EPSS 0.002
CVE-2025-55834
A Cross Site Scripting vulnerability in JeeWMS v.3.7 and before allows a remote attacker to obtain sensitive information via the logController.do component
Published 2025-09-16 · Analyzed
6.1EPSS 0.003
CVE-2026-3028
erzhongxmu JEEWMS JeecgListDemoController.java doAdd cross site scripting
Published 2026-02-23 · Analyzed
6.1EPSS 0.003