VendorsJEECGjimureportall versions
Vulnerabilities

JEECG JimuReport

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-2023-4450
jeecgboot JimuReport Template injection
Published 2023-08-21 · Modified
9.8EPSS 0.116
CVE-2025-66913
JimuReport thru version 2.1.3 is vulnerable to remote code execution when processing user-controlled H2 JDBC URLs. The application passes the attacker-supplied JDBC URL directly to the H2 driver, allowing the use of certain directives to execute arbitrary Java code. A different vulnerability than CVE-2025-10770.
Published 2026-01-08 · Analyzed
9.8EPSS 0.011
CVE-2023-6307
jeecgboot JimuReport image path traversal
Published 2023-11-27 · Modified
9.8EPSS 0.008
CVE-2025-10771
jeecgboot JimuReport DB2 JDBC testConnection deserialization
Published 2025-09-21 · Analyzed
9.8EPSS 0.006
CVE-2024-44893
An issue in the component /jeecg-boot/jmreport/dict/list of JimuReport v1.7.8 allows attacker to escalate privileges via a crafted GET request.
Published 2024-09-10 · Analyzed
9.8EPSS 0.005
CVE-2025-8963
jeecgboot JimuReport Data Large Screen Template testConnection deserialization
Published 2025-08-14 · Analyzed
9.8EPSS 0.005
CVE-2025-10770
jeecgboot JimuReport MySQL JDBC testConnection deserialization
Published 2025-09-21 · Analyzed
6.5EPSS 0.004