VendorsJEECGjeecg_bootall versions
Vulnerabilities

JEECG Boot

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

57CVEs
CVE-2025-61189
Jeecgboot versions 3.8.2 and earlier are affected by a path traversal vulnerability. The endpoint is /sys/comment/addFile. This vulnerability allows attackers to upload files with system-whitelisted extensions to the system directory /opt, instead of the /opt/upFiles directory specified by the web server.
Published 2025-10-01 · Analyzed
6.3EPSS 0.003
CVE-2025-61188
Jeecgboot versions 3.8.2 and earlier are affected by a path traversal vulnerability. This vulnerability allows attackers to upload files with system-whitelisted extensions to the system directory /opt, instead of the /opt/upFiles directory specified by the web server.
Published 2025-10-01 · Analyzed
6.3EPSS 0.003
CVE-2021-44585
A Cross Site Scripting (XSS) vulnerabilitiy exits in jeecg-boot 3.0 in /jeecg-boot/jmreport/view with a mouseover event.
Published 2022-03-10 · Modified
6.1EPSS 0.009
CVE-2023-38905
SQL injection vulnerability in Jeecg-boot v.3.5.0 and before allows a local attacker to cause a denial of service via the Benchmark, PG_Sleep, DBMS_Lock.Sleep, Waitfor, DECODE, and DBMS_PIPE.RECEIVE_MESSAGE functions.
Published 2023-08-17 · Modified
5.5EPSS 0.003
CVE-2022-45205
Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/dict/queryTableData.
Published 2022-11-25 · Modified
5.3EPSS 0.006
CVE-2025-10977
JeecgBoot deleteBatch improper authorization
Published 2025-09-25 · Analyzed
5.3EPSS 0.004
CVE-2025-10976
JeecgBoot getDepartUserList improper authorization
Published 2025-09-25 · Analyzed
5.3EPSS 0.004
CVE-2025-15121
JeecgBoot getDeptRoleByUserId information disclosure
Published 2025-12-28 · Analyzed
4.9EPSS 0.004
CVE-2026-2111
JeecgBoot Retrieval-Augmented Generation edit path traversal
Published 2026-02-07 · Analyzed
4.3EPSS 0.005
CVE-2022-45210
Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/user/deleteRecycleBin.
Published 2022-11-25 · Modified
4.3EPSS 0.005
CVE-2022-45208
Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/user/putRecycleBin.
Published 2022-11-25 · Modified
4.3EPSS 0.005
CVE-2025-15120
JeecgBoot getDeptRoleList improper authorization
Published 2025-12-28 · Analyzed
3.1EPSS 0.003
CVE-2025-15122
JeecgBoot datarule loadDatarule improper authorization
Published 2025-12-28 · Analyzed
3.1EPSS 0.003
CVE-2025-15123
JeecgBoot datarule improper authorization
Published 2025-12-28 · Analyzed
3.1EPSS 0.003
CVE-2025-15124
JeecgBoot list getParameterMap improper authorization
Published 2025-12-28 · Analyzed
3.1EPSS 0.003
CVE-2025-15125
JeecgBoot queryDepartPermission improper authorization
Published 2025-12-28 · Analyzed
3.1EPSS 0.003
CVE-2025-15119
JeecgBoot list queryPageList improper authorization
Published 2025-12-28 · Analyzed
3.1EPSS 0.003
← Prev2 / 2