📦 Jeecg Boot

by Jeecg

🔍 What is Jeecg Boot?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-41544

CRITICAL CVSS 9.8 Dec 30, 2023

This is a Server-Side Template Injection (SSTI) vulnerability in jeecg-boot version 3.5.3 that allows remote attackers to execute arbitrary code via crafted HTTP requests to the /jmreport/loadTableDat...

CVE-2023-41542

CRITICAL CVSS 9.8 Dec 30, 2023

This SQL injection vulnerability in jeecg-boot version 3.5.3 allows remote attackers to execute arbitrary SQL commands via the jmreport/qurestSql component. Attackers can escalate privileges, access s...

CVE-2023-42268

CRITICAL CVSS 9.8 Sep 8, 2023

Jeecg Boot versions up to 3.5.3 contain a SQL injection vulnerability in the /jeecg-boot/jmreport/show component. This allows attackers to execute arbitrary SQL commands on the database. Organizations...

CVE-2023-34659

CRITICAL CVSS 9.8 Jun 16, 2023

Jeecg-Boot versions 3.5.0 and 3.5.1 contain a SQL injection vulnerability in the id parameter of the /jeecg-boot/jmreport/show interface. This allows attackers to execute arbitrary SQL commands on the...

CVE-2022-22880

CRITICAL CVSS 9.8 Feb 16, 2022

Jeecg-boot v3.0 contains a SQL injection vulnerability in the /jeecg-boot/sys/user/queryUserByDepId endpoint via the code parameter. This allows attackers to execute arbitrary SQL commands on the data...

CVE-2021-46089

CRITICAL CVSS 9.8 Jan 25, 2022

CVE-2021-46089 is a critical SQL injection vulnerability in JeecgBoot 3.0 that allows attackers to execute arbitrary SQL commands with root database privileges. This affects all organizations using vu...

CVE-2020-28088

CRITICAL CVSS 9.8 Aug 6, 2021

This vulnerability allows attackers to upload arbitrary files to the jeecg-boot CMS system through the /jeecg-boot/sys/common/upload endpoint. Attackers can then execute arbitrary code on the server, ...

CVE-2023-41578

HIGH CVSS 7.5 Sep 8, 2023

Jeecg Boot up to version 3.5.3 contains an arbitrary file read vulnerability in the /testConnection interface. This allows attackers to read sensitive files from the server filesystem without authenti...

CVE-2020-28087

HIGH CVSS 7.5 Aug 6, 2021

This SQL injection vulnerability in jeecg-boot CMS allows attackers to execute arbitrary SQL commands through the /jeecg boot/sys/dict/loadtreedata endpoint. Attackers can access, modify, or delete se...

CVE-2026-2945

MEDIUM CVSS 6.3 Feb 22, 2026

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in JeecgBoot 3.9.0 that allows attackers to make the server send HTTP requests to arbitrary internal or external systems. Attacker...

CVE-2026-2555

MEDIUM CVSS 5.0 Feb 16, 2026

A deserialization vulnerability in JeecgBoot 3.9.1 allows remote attackers to execute arbitrary code by manipulating the importDocumentFromZip function in the AI knowledge controller. This affects sys...

CVE-2026-2111

MEDIUM CVSS 4.3 Feb 7, 2026

JeecgBoot versions up to 3.9.0 contain a path traversal vulnerability in the Retrieval-Augmented Generation Module's /airag/knowledge/doc/edit endpoint. Attackers can manipulate the filePath parameter...

CVE-2025-14909

MEDIUM CVSS 4.3 Dec 19, 2025

This vulnerability in JeecgBoot allows attackers to remotely manipulate user sessions through the SysUserOnlineController function. It affects JeecgBoot versions up to 3.9.0, potentially enabling unau...

CVE-2025-14908

MEDIUM CVSS 6.3 Dec 19, 2025

CVE-2025-14908 is an authentication bypass vulnerability in JeecgBoot's multi-tenant management module that allows attackers to manipulate tenant ID parameters without proper authentication. This affe...

CVE-2025-61189

MEDIUM CVSS 6.3 Oct 1, 2025

Jeecgboot versions 3.8.2 and earlier contain a path traversal vulnerability in the /sys/comment/addFile endpoint that allows attackers to upload files with whitelisted extensions to the system's /opt ...

CVE-2025-10981

MEDIUM CVSS 4.3 Sep 26, 2025

This vulnerability in JeecgBoot allows unauthorized access to the tenant export function via the /sys/tenant/exportXls endpoint. Attackers can remotely exploit this improper authorization flaw to pote...

CVE-2025-10980

MEDIUM CVSS 4.3 Sep 26, 2025

JeecgBoot up to version 3.8.2 contains an improper authorization vulnerability in the /sys/position/exportXls endpoint that allows remote attackers to access unauthorized functionality. This affects a...

CVE-2025-10978

MEDIUM CVSS 4.3 Sep 25, 2025

This vulnerability in JeecgBoot allows unauthorized access to the user export functionality via the /sys/user/exportXls endpoint. Attackers can exploit this to export sensitive user data without prope...

CVE-2025-10979

MEDIUM CVSS 4.3 Sep 25, 2025

JeecgBoot up to version 3.8.2 has an improper authorization vulnerability in the /sys/role/exportXls endpoint that allows unauthorized access to role export functionality. This affects all JeecgBoot d...

CVE-2025-15126

LOW CVSS 3.1 Dec 28, 2025

This CVE describes an improper authorization vulnerability in JeecgBoot's getPositionUserList function. Attackers can manipulate the positionId parameter to potentially access unauthorized user positi...

CVE-2025-15124

LOW CVSS 3.1 Dec 28, 2025

This vulnerability in JeecgBoot allows attackers to bypass authorization checks by manipulating the departId parameter in the /sys/sysDepartPermission/list endpoint. It enables unauthorized access to ...

CVE-2025-15125

LOW CVSS 3.1 Dec 28, 2025

This CVE describes an improper authorization vulnerability in JeecgBoot's queryDepartPermission function. Attackers can manipulate the departId parameter to potentially access unauthorized department ...

CVE-2025-15123

LOW CVSS 3.1 Dec 28, 2025

JeecgBoot up to version 3.9.0 contains an improper authorization vulnerability in the /sys/sysDepartPermission/datarule/ endpoint. This allows remote attackers to potentially bypass intended access co...

CVE-2025-15122

LOW CVSS 3.1 Dec 28, 2025

This CVE describes an improper authorization vulnerability in JeecgBoot's loadDatarule function that allows attackers to manipulate departId/roleId parameters. Attackers could potentially access unaut...

CVE-2025-15121

LOW CVSS 2.4 Dec 28, 2025

This vulnerability in JeecgBoot allows attackers to exploit the getDeptRoleByUserId function by manipulating the departId parameter, leading to unauthorized information disclosure. It affects JeecgBoo...

CVE-2025-15120

LOW CVSS 3.1 Dec 28, 2025

This CVE describes an improper authorization vulnerability in JeecgBoot's getDeptRoleList function. Attackers can manipulate the departId parameter to potentially access unauthorized department role i...

CVE-2025-15119

LOW CVSS 3.1 Dec 28, 2025

This vulnerability in JeecgBoot allows attackers to bypass authorization checks by manipulating the deptId parameter in the /sys/sysDepartRole/list endpoint. It enables unauthorized access to departme...