VendorsJEECGjeecg_bootall versions
Vulnerabilities

JEECG Boot

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

57CVEs
CVE-2021-46089
In JeecgBoot 3.0, there is a SQL injection vulnerability that can operate the database with root privileges.
Published 2022-01-25 · Modified
10.0EPSS 0.020
CVE-2023-38992
jeecg-boot v3.5.1 was discovered to contain a SQL injection vulnerability via the title parameter at /sys/dict/loadTreeData.
Published 2023-07-28 · Modified
9.8EPSS 0.734
CVE-2024-48307
JeecgBoot v3.7.1 was discovered to contain a SQL injection vulnerability via the component /onlDragDatasetHead/getTotalData.
Published 2024-10-31 · Analyzed
9.8EPSS 0.443
CVE-2023-1454
jeecg-boot qurestSql sql injection
Published 2023-03-17 · Modified
9.8EPSS 0.358
CVE-2023-34659
jeecg-boot 3.5.0 and 3.5.1 have a SQL injection vulnerability the id parameter of the /jeecg-boot/jmreport/show interface.
Published 2023-06-16 · Modified
9.8EPSS 0.125
CVE-2023-41544
SSTI injection vulnerability in jeecg-boot version 3.5.3, allows remote attackers to execute arbitrary code via crafted HTTP request to the /jmreport/loadTableData component.
Published 2023-12-30 · Modified
9.8EPSS 0.027
CVE-2020-28088
An arbitrary file upload vulnerability in /jeecg-boot/sys/common/upload of jeecg-boot CMS 2.3 allows attackers to execute arbitrary code.
Published 2021-08-06 · Modified
9.8EPSS 0.023
CVE-2023-40989
SQL injection vulnerbility in jeecgboot jeecg-boot v 3.0, 3.5.3 that allows a remote attacker to execute arbitrary code via a crafted request to the report/jeecgboot/jmreport/queryFieldBySql component.
Published 2023-09-22 · Modified
9.8EPSS 0.022
CVE-2024-43028
A command injection vulnerability in the component /jmreport/show of jeecg boot v3.0.0 to v3.5.3 allows attackers to execute arbitrary code via a crafted HTTP request.
Published 2026-04-01 · Analyzed
9.8EPSS 0.015
CVE-2022-22880
Jeecg-boot v3.0 was discovered to contain a SQL injection vulnerability via the code parameter in /jeecg-boot/sys/user/queryUserByDepId.
Published 2022-02-16 · Modified
9.8EPSS 0.014
CVE-2022-22881
Jeecg-boot v3.0 was discovered to contain a SQL injection vulnerability via the code parameter in /sys/user/queryUserComponentData.
Published 2022-02-16 · Modified
9.8EPSS 0.014
CVE-2022-47105
Jeecg-boot v3.4.4 was discovered to contain a SQL injection vulnerability via the component /sys/dict/queryTableData.
Published 2023-01-19 · Modified
9.8EPSS 0.011
CVE-2023-1784
jeecg-boot API Documentation improper authentication
Published 2023-03-31 · Modified
9.8EPSS 0.010
CVE-2022-45207
Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component updateNullByEmptyString.
Published 2022-11-25 · Modified
9.8EPSS 0.010
CVE-2023-41543
SQL injection vulnerability in jeecg-boot v3.5.3, allows remote attackers to escalate privileges and obtain sensitive information via the component /sys/replicate/check.
Published 2023-12-30 · Modified
9.8EPSS 0.009
CVE-2023-42268
Jeecg boot up to v3.5.3 was discovered to contain a SQL injection vulnerability via the component /jeecg-boot/jmreport/show.
Published 2023-09-08 · Modified
9.8EPSS 0.009
CVE-2023-41542
SQL injection vulnerability in jeecg-boot version 3.5.3, allows remote attackers to escalate privileges and obtain sensitive information via the jmreport/qurestSql component.
Published 2023-12-30 · Modified
9.8EPSS 0.009
CVE-2023-1741
jeecg-boot Sleep Command SysDictMapper.java sql injection
Published 2023-03-30 · Modified
9.8EPSS 0.008
CVE-2022-2647
jeecg-boot unrestricted upload
Published 2022-08-04 · Modified
9.8EPSS 0.008
CVE-2022-45206
Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/duplicate/check.
Published 2022-11-25 · Modified
9.8EPSS 0.008
CVE-2024-40489
There is an injection vulnerability in jeecg boot versions 3.0.0 to 3.5.3 due to lax character filtering, which allows attackers to execute arbitrary code on components through specially crafted HTTP requests.
Published 2026-04-01 · Analyzed
9.8EPSS 0.005
CVE-2026-2822
JeecgBoot Backend airag_app,1,create_by sql injection
Published 2026-02-20 · Analyzed
8.8EPSS 0.005
CVE-2026-1746
JeecgBoot Online Report API loadDictItemByKeyword sql injection
Published 2026-02-02 · Analyzed
8.8EPSS 0.005
CVE-2025-10318
JeecgBoot WebSocket Message sendWebSocketMsg improper authorization
Published 2025-09-12 · Analyzed
8.8EPSS 0.004
CVE-2025-10707
JeecgBoot sendMsg improper authorization
Published 2025-09-19 · Analyzed
8.8EPSS 0.004
CVE-2025-14909
JeecgBoot SysUserOnlineController.java SysUserOnlineController user session
Published 2025-12-19 · Analyzed
8.1EPSS 0.005
CVE-2025-14908
JeecgBoot Multi-Tenant Management SysTenantController.java improper authentication
Published 2025-12-19 · Analyzed
8.1EPSS 0.003
CVE-2020-28087
A SQL injection vulnerability in /jeecg boot/sys/dict/loadtreedata of jeecg-boot CMS 2.3 allows attackers to access sensitive database information.
Published 2021-08-06 · Modified
7.5EPSS 0.016
CVE-2023-41578
Jeecg boot up to v3.5.3 was discovered to contain an arbitrary file read vulnerability via the interface /testConnection.
Published 2023-09-08 · Modified
7.5EPSS 0.009
CVE-2025-4533
JeecgBoot Document Library Upload zip unzipFile resource consumption
Published 2025-05-11 · Analyzed
7.5EPSS 0.007
CVE-2026-2555
JeecgBoot Retrieval-Augmented Generation AiragKnowledgeController.java importDocumentFromZip deserialization
Published 2026-02-16 · Analyzed
7.5EPSS 0.006
CVE-2025-15126
JeecgBoot getPositionUserList improper authorization
Published 2025-12-28 · Analyzed
7.5EPSS 0.004
CVE-2023-47467
Directory Traversal vulnerability in jeecg-boot v.3.6.0 allows a remote privileged attacker to obtain sensitive information via the file directory structure.
Published 2023-11-22 · Modified
6.5EPSS 0.011
CVE-2023-34660
jjeecg-boot V3.5.0 has an unauthorized arbitrary file upload in /jeecg-boot/jmreport/upload interface.
Published 2023-06-16 · Modified
6.5EPSS 0.006
CVE-2025-10980
JeecgBoot exportXls improper authorization
Published 2025-09-25 · Analyzed
6.5EPSS 0.004
CVE-2026-2945
JeecgBoot uploadImgByHttp server-side request forgery
Published 2026-02-22 · Analyzed
6.5EPSS 0.004
CVE-2025-10978
JeecgBoot Filter exportXls improper authorization
Published 2025-09-25 · Analyzed
6.5EPSS 0.004
CVE-2025-10979
JeecgBoot exportXls improper authorization
Published 2025-09-25 · Analyzed
6.5EPSS 0.004
CVE-2025-10981
JeecgBoot exportXls improper authorization
Published 2025-09-26 · Analyzed
6.5EPSS 0.004
CVE-2025-10319
JeecgBoot Tenant Log Export exportLog improper authorization
Published 2025-09-12 · Analyzed
6.5EPSS 0.003
1 / 2Next →