VendorsJishenghuajsherpany version
Vulnerabilities

Jishenghua Jsherp any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

15CVEs
CVE-2025-51742
An issue was discovered in jishenghua JSH_ERP 2.3.1. The /material/getMaterialEnableSerialNumberList endpoint passes the search query parameter directly to parseObject(), introducing a Fastjson deserialization vulnerability that can lead to RCE via JDBC payloads.
Published 2025-11-25 · Analyzed
9.8EPSS 0.005
CVE-2025-51743
An issue was discovered in jishenghua JSH_ERP 2.3.1. The /materialCategory/addMaterialCategory endpoint is vulnerable to fastjson deserialization attacks.
Published 2025-11-25 · Analyzed
9.8EPSS 0.005
CVE-2025-51744
An issue was discovered in jishenghua JSH_ERP 2.3.1. The /user/addUser endpoint is vulnerable to fastjson deserialization attacks.
Published 2025-11-25 · Analyzed
9.8EPSS 0.005
CVE-2025-51745
An issue was discovered in jishenghua JSH_ERP 2.3.1. The /role/addcan endpoint is vulnerable to fastjson deserialization attacks.
Published 2025-11-25 · Analyzed
9.8EPSS 0.005
CVE-2025-51746
An issue was discovered in jishenghua JSH_ERP 2.3.1. The /serialNumber/addSerialNumber endpoint is vulnerable to fastjson deserialization attacks.
Published 2025-11-25 · Analyzed
9.8EPSS 0.005
CVE-2026-1546
jishenghua jshERP com.jsh.erp.datasource.mappers.DepotItemMapperEx importItemExcel getBillItemByParam sql injection
Published 2026-01-28 · Analyzed
9.8EPSS 0.004
CVE-2025-60801
jshERP up to commit fbda24da was discovered to contain an unauthenticated remote code execution (RCE) vulnerability via the jsh_erp function.
Published 2025-10-24 · Analyzed
8.2EPSS 0.005
CVE-2025-7947
jshERP Account delete improper authorization
Published 2025-07-22 · Analyzed
8.1EPSS 0.004
CVE-2025-60800
Incorrect access control in the /jshERP-boot/user/info interface of jshERP up to commit 90c411a allows attackers to access sensitive information via a crafted GET request.
Published 2025-10-28 · Analyzed
7.5EPSS 0.003
CVE-2025-7566
jshERP SystemConfigController.java exportExcelByParam path traversal
Published 2025-07-14 · Analyzed
7.2EPSS 0.006
CVE-2025-7948
jshERP updatePwd password recovery
Published 2025-07-22 · Analyzed
6.5EPSS 0.004
CVE-2025-67341
jshERP versions 3.5 and earlier are affected by a stored XSS vulnerability. This vulnerability allows attackers to upload PDF files containing XSS payloads. Additionally, these PDF files can be accessed via static URLs, making them accessible to all users.
Published 2025-12-12 · Analyzed
4.6EPSS 0.002
CVE-2025-67344
jshERP v3.5 and earlier is affected by a stored Cross Site Scripting (XSS) vulnerability via the /msg/add endpoint.
Published 2025-12-12 · Analyzed
4.6EPSS 0.002
CVE-2026-1549
jishenghua jshERP PluginController uploadPluginConfigFile path traversal
Published 2026-01-28 · Analyzed
4.3EPSS 0.005
CVE-2026-1588
jishenghua jshERP installByPath install path traversal
Published 2026-01-29 · Analyzed
3.3EPSS 0.006