VendorsJEECGjeecg_bootany version
Vulnerabilities

JEECG Boot any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

35CVEs
CVE-2023-41544
SSTI injection vulnerability in jeecg-boot version 3.5.3, allows remote attackers to execute arbitrary code via crafted HTTP request to the /jmreport/loadTableData component.
Published 2023-12-30 · Modified
9.8EPSS 0.027
CVE-2024-43028
A command injection vulnerability in the component /jmreport/show of jeecg boot v3.0.0 to v3.5.3 allows attackers to execute arbitrary code via a crafted HTTP request.
Published 2026-04-01 · Analyzed
9.8EPSS 0.015
CVE-2022-22881
Jeecg-boot v3.0 was discovered to contain a SQL injection vulnerability via the code parameter in /sys/user/queryUserComponentData.
Published 2022-02-16 · Modified
9.8EPSS 0.014
CVE-2022-22880
Jeecg-boot v3.0 was discovered to contain a SQL injection vulnerability via the code parameter in /jeecg-boot/sys/user/queryUserByDepId.
Published 2022-02-16 · Modified
9.8EPSS 0.014
CVE-2023-41543
SQL injection vulnerability in jeecg-boot v3.5.3, allows remote attackers to escalate privileges and obtain sensitive information via the component /sys/replicate/check.
Published 2023-12-30 · Modified
9.8EPSS 0.009
CVE-2023-42268
Jeecg boot up to v3.5.3 was discovered to contain a SQL injection vulnerability via the component /jeecg-boot/jmreport/show.
Published 2023-09-08 · Modified
9.8EPSS 0.009
CVE-2023-41542
SQL injection vulnerability in jeecg-boot version 3.5.3, allows remote attackers to escalate privileges and obtain sensitive information via the jmreport/qurestSql component.
Published 2023-12-30 · Modified
9.8EPSS 0.009
CVE-2022-2647
jeecg-boot unrestricted upload
Published 2022-08-04 · Modified
9.8EPSS 0.008
CVE-2024-40489
There is an injection vulnerability in jeecg boot versions 3.0.0 to 3.5.3 due to lax character filtering, which allows attackers to execute arbitrary code on components through specially crafted HTTP requests.
Published 2026-04-01 · Analyzed
9.8EPSS 0.005
CVE-2026-2822
JeecgBoot Backend airag_app,1,create_by sql injection
Published 2026-02-20 · Analyzed
8.8EPSS 0.005
CVE-2025-10318
JeecgBoot WebSocket Message sendWebSocketMsg improper authorization
Published 2025-09-12 · Analyzed
8.8EPSS 0.004
CVE-2025-10707
JeecgBoot sendMsg improper authorization
Published 2025-09-19 · Analyzed
8.8EPSS 0.004
CVE-2025-14909
JeecgBoot SysUserOnlineController.java SysUserOnlineController user session
Published 2025-12-19 · Analyzed
8.1EPSS 0.005
CVE-2025-14908
JeecgBoot Multi-Tenant Management SysTenantController.java improper authentication
Published 2025-12-19 · Analyzed
8.1EPSS 0.003
CVE-2023-41578
Jeecg boot up to v3.5.3 was discovered to contain an arbitrary file read vulnerability via the interface /testConnection.
Published 2023-09-08 · Modified
7.5EPSS 0.009
CVE-2025-4533
JeecgBoot Document Library Upload zip unzipFile resource consumption
Published 2025-05-11 · Analyzed
7.5EPSS 0.007
CVE-2025-15126
JeecgBoot getPositionUserList improper authorization
Published 2025-12-28 · Analyzed
7.5EPSS 0.004
CVE-2025-10980
JeecgBoot exportXls improper authorization
Published 2025-09-25 · Analyzed
6.5EPSS 0.004
CVE-2025-10978
JeecgBoot Filter exportXls improper authorization
Published 2025-09-25 · Analyzed
6.5EPSS 0.004
CVE-2025-10979
JeecgBoot exportXls improper authorization
Published 2025-09-25 · Analyzed
6.5EPSS 0.004
CVE-2025-10981
JeecgBoot exportXls improper authorization
Published 2025-09-26 · Analyzed
6.5EPSS 0.004
CVE-2025-10319
JeecgBoot Tenant Log Export exportLog improper authorization
Published 2025-09-12 · Analyzed
6.5EPSS 0.003
CVE-2025-61189
Jeecgboot versions 3.8.2 and earlier are affected by a path traversal vulnerability. The endpoint is /sys/comment/addFile. This vulnerability allows attackers to upload files with system-whitelisted extensions to the system directory /opt, instead of the /opt/upFiles directory specified by the web server.
Published 2025-10-01 · Analyzed
6.3EPSS 0.003
CVE-2025-61188
Jeecgboot versions 3.8.2 and earlier are affected by a path traversal vulnerability. This vulnerability allows attackers to upload files with system-whitelisted extensions to the system directory /opt, instead of the /opt/upFiles directory specified by the web server.
Published 2025-10-01 · Analyzed
6.3EPSS 0.003
CVE-2023-38905
SQL injection vulnerability in Jeecg-boot v.3.5.0 and before allows a local attacker to cause a denial of service via the Benchmark, PG_Sleep, DBMS_Lock.Sleep, Waitfor, DECODE, and DBMS_PIPE.RECEIVE_MESSAGE functions.
Published 2023-08-17 · Modified
5.5EPSS 0.003
CVE-2025-10977
JeecgBoot deleteBatch improper authorization
Published 2025-09-25 · Analyzed
5.3EPSS 0.004
CVE-2025-10976
JeecgBoot getDepartUserList improper authorization
Published 2025-09-25 · Analyzed
5.3EPSS 0.004
CVE-2025-15121
JeecgBoot getDeptRoleByUserId information disclosure
Published 2025-12-28 · Analyzed
4.9EPSS 0.004
CVE-2026-2111
JeecgBoot Retrieval-Augmented Generation edit path traversal
Published 2026-02-07 · Analyzed
4.3EPSS 0.005
CVE-2025-15120
JeecgBoot getDeptRoleList improper authorization
Published 2025-12-28 · Analyzed
3.1EPSS 0.003
CVE-2025-15122
JeecgBoot datarule loadDatarule improper authorization
Published 2025-12-28 · Analyzed
3.1EPSS 0.003
CVE-2025-15123
JeecgBoot datarule improper authorization
Published 2025-12-28 · Analyzed
3.1EPSS 0.003
CVE-2025-15124
JeecgBoot list getParameterMap improper authorization
Published 2025-12-28 · Analyzed
3.1EPSS 0.003
CVE-2025-15125
JeecgBoot queryDepartPermission improper authorization
Published 2025-12-28 · Analyzed
3.1EPSS 0.003
CVE-2025-15119
JeecgBoot list queryPageList improper authorization
Published 2025-12-28 · Analyzed
3.1EPSS 0.003