Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

JEEWMS — Vulnerabilities & Security Advisories 18

All 18 CVE vulnerabilities found in JEEWMS, with AI-generated Chinese analysis, references, and POCs.

This vulnerability aggregation page focuses on Jeewms, a Java-based enterprise content management system developed by Jeewx, categorized under web application security weaknesses. The page collects vulnerability records spanning from 2019 to 2024, capturing known security issues affecting various versions of the software released during this period. It includes details on remote code execution, SQL injection, and cross-site scripting flaws that have been publicly disclosed or verified. Here, users can track Jeewx's security advisories and release notes to understand how the vendor responds to reported issues. It allows for a deep dive into specific weakness classes impacting the product, helping developers and security analysts identify common coding errors or architectural flaws. You can also look up the product's vulnerability history to assess its overall security posture over time, comparing past incidents with current remediation efforts. This resource serves as a centralized reference for evaluating risks associated with Jeewms deployments, enabling organizations to prioritize patching and mitigate potential threats effectively. By aggregating these data points, the page provides a clear view of the product's security landscape without requiring external sources.

Vendor: erzhongxmu

CVE IDTitleCVSSSeverityPublished
CVE-2026-11458 erzhongxmu JeeWMS Boot Actuator Endpoint actuator information disclosure CWE-200 5.3 Medium2026-06-07
CVE-2026-11457 erzhongxmu JeeWMS JimuReport test-connection Endpoint testConnection injection CWE-74 7.3 High2026-06-07
CVE-2026-3028 erzhongxmu JEEWMS JeecgListDemoController.java doAdd cross site scripting CWE-79 4.3 Medium2026-02-23
CVE-2026-3027 erzhongxmu JEEWMS UEditor getContent.jsp cross site scripting CWE-79 4.3 Medium2026-02-23
CVE-2026-3026 erzhongxmu JEEWMS UEditor getRemoteImage.jsp server-side request forgery CWE-918 7.3 High2026-02-23
CVE-2025-5390 JeeWMS File filedeal.do filedeal access control CWE-284 6.3 Medium2025-05-31
CVE-2025-5389 JeeWMS File generateController.do dogenerateOne2Many access control CWE-284 6.3 Medium2025-05-31
CVE-2025-5388 JeeWMS generateController.do dogenerate sql injection CWE-89 6.3 Medium2025-05-31
CVE-2025-5387 JeeWMS File generateController.do dogenerate access control CWE-284 6.3 Medium2025-05-31
CVE-2025-5386 JeeWMS cgformTransController.do transEditor sql injection CWE-89 6.3 Medium2025-05-31
CVE-2025-5385 JeeWMS cgformTemplateController.do doAdd path traversal CWE-22 6.3 Medium2025-05-31
CVE-2025-5384 JeeWMS cgAutoListController.do CgAutoListController sql injection CWE-89 6.3 Medium2025-05-31
CVE-2025-0392 Guangzhou Huayi Intelligent Technology Jeewms graphReportController.do datagridGraph sql injection CWE-89 6.3 Medium2025-01-11
CVE-2025-0391 Guangzhou Huayi Intelligent Technology Jeewms CgFormBuildController. java saveOrUpdate sql injection CWE-89 6.3 Medium2025-01-11
CVE-2025-0390 Guangzhou Huayi Intelligent Technology Jeewms wmOmNoticeHController.do path traversal CWE-24 5.3 Medium2025-01-11
CVE-2024-12347 Guangzhou Huayi Intelligent Technology Jeewms Druid Monitoring Interface index.html improper authorization CWE-285 5.3 Medium2024-12-08
CVE-2024-11961 Guangzhou Huayi Intelligent Technology Jeewms WmOmNoticeHController.java preHandle information disclosure CWE-200 5.3 Medium2024-11-28
CVE-2024-11251 erzhongxmu Jeewms AuthInterceptor cgReportController.do sql injection CWE-89 6.3 Medium2024-11-15

All 18 known CVE vulnerabilities affecting JEEWMS with full Chinese analysis, references, and POCs where available.