📦 Jeewms

by Huayi Tec

🔍 What is Jeewms?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-57761

HIGH CVSS 8.1 Jan 15, 2025

An arbitrary file upload vulnerability in JeeWMS allows attackers to upload malicious files that can lead to remote code execution. This affects all JeeWMS installations before version 2025.01.01. Att...

CVE-2026-3028

MEDIUM CVSS 4.3 Feb 23, 2026

A stored cross-site scripting (XSS) vulnerability exists in erzhongxmu JEEWMS up to version 3.7, specifically in the doAdd function of JeecgListDemoController.java. This allows remote attackers to inj...

CVE-2025-70311

MEDIUM CVSS 6.5 Feb 3, 2026

JEEWMS 1.0 contains a SQL injection vulnerability in the /systemControl.do interface where attackers can inject malicious SQL through id1 and id2 parameters. This allows unauthorized database access a...

CVE-2025-5390

MEDIUM CVSS 6.3 May 31, 2025

This critical vulnerability in JeeWMS allows remote attackers to bypass access controls on the file handling component, potentially accessing or manipulating files without proper authorization. All Je...

CVE-2025-5388

MEDIUM CVSS 6.3 May 31, 2025

This critical SQL injection vulnerability in JeeWMS allows attackers to execute arbitrary SQL commands through the /generateController.do?dogenerate endpoint. All JeeWMS installations up to version 20...

CVE-2025-5386

MEDIUM CVSS 6.3 May 31, 2025

This critical SQL injection vulnerability in JeeWMS allows remote attackers to execute arbitrary SQL commands through the transEditor function. Any organization using JeeWMS up to May 4, 2025 is affec...

CVE-2025-5384

MEDIUM CVSS 6.3 May 31, 2025

CVE-2025-5384 is a critical SQL injection vulnerability in JeeWMS that allows remote attackers to execute arbitrary SQL commands through the /cgAutoListController.do?datagrid endpoint. This affects al...

CVE-2025-0392

MEDIUM CVSS 6.3 Jan 11, 2025

This critical SQL injection vulnerability in Jeewms allows remote attackers to execute arbitrary SQL commands by manipulating the store_code parameter in the datagridGraph function. Organizations usin...

CVE-2025-0390

MEDIUM CVSS 5.3 Jan 11, 2025

This critical path traversal vulnerability in Jeewms allows attackers to access arbitrary files on the server by manipulating the /wmOmNoticeHController.do endpoint. Attackers can exploit this remotel...

CVE-2024-12347

MEDIUM CVSS 5.3 Dec 9, 2024

This CVE describes an improper authorization vulnerability in the Druid monitoring interface of Jeewms warehouse management software. Attackers can remotely access sensitive monitoring data without au...