Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

JeecgBoot — Vulnerabilities & Security Advisories 47

All 47 CVE vulnerabilities found in JeecgBoot, with AI-generated Chinese analysis, references, and POCs.

This page catalogs known security vulnerabilities and weaknesses associated with the JeecgBoot open-source development platform. It focuses on aggregate data related to common weakness types, such as injection flaws, cross-site scripting, and insecure configurations, providing a centralized view of the product's security posture. The content collected on this page includes documented defects reported by security researchers, developers, and third-party auditors, covering a comprehensive historical time range that reflects both past patches and currently unaddressed risks. By reviewing this aggregated information, users can effectively track vendor advisories and official responses to emerging threats, gaining insight into how the JeecgBoot team handles security incidents over time. Additionally, the page allows for a deeper understanding of specific weakness classes that frequently impact this framework, helping developers identify patterns in code vulnerabilities. Readers can also look up the complete vulnerability history of JeecgBoot to assess long-term stability and the frequency of security updates, facilitating informed decisions regarding platform adoption and maintenance. This resource serves as a factual reference point for security professionals and IT administrators seeking to evaluate the risk profile of JeecgBoot in enterprise environments. It does not offer subjective opinions or promotional material, but rather presents verified data points that contribute to a holistic understanding of the software's security landscape.

Vendor: n/a

CVE IDTitleCVSSSeverityPublished
CVE-2026-19000 JeecgBoot Anonymous Chat Attachment send server-side request forgery CWE-918 7.3 High2026-08-06
CVE-2026-58377 JeecgBoot 3.9.2 - Missing Authorization on OpenAPI Credential Management Endpoints Exposes Access/Secret Keys CWE-862 8.1 High2026-06-30
CVE-2026-11502 JeecgBoot Third-Party Login ThirdLoginController.java HttpServletResponse.sendRedirect redirect CWE-601 3.1 Low2026-06-08
CVE-2026-11464 JeecgBoot User List Endpoint SysUserController.java queryPageList information disclosure CWE-200 3.1 Low2026-06-07
CVE-2026-10240 JeecgBoot test server-side request forgery CWE-918 6.3 Medium2026-06-01
CVE-2026-10239 JeecgBoot edit WordUtil.addImage server-side request forgery CWE-918 6.3 Medium2026-06-01
CVE-2026-9604 JeecgBoot AiragModelController access control CWE-284 4.3 Medium2026-05-26
CVE-2026-9581 JeecgBoot add access control CWE-284 6.3 Medium2026-05-26
CVE-2026-9580 JeecgBoot selectDepart LoginController.selectDepart access control CWE-284 7.3 High2026-05-26
CVE-2026-9579 JeecgBoot SysUser userEdit user.getUsername access control CWE-284 6.3 Medium2026-05-26
CVE-2026-9373 JeecgBoot OpenAPI Endpoint call improper authentication CWE-287 3.7 Low2026-05-24
CVE-2026-8196 JeecgBoot mLogin Endpoint LoginController.java authorization CWE-639 3.7 Low2026-05-09
CVE-2026-8195 JeecgBoot SVG File CommonController.java cross site scripting CWE-79 4.3 Medium2026-05-09
CVE-2026-8114 JeecgBoot JSON Object loadTreeData sql injection CWE-89 6.3 Medium2026-05-07
CVE-2026-7605 JeecgBoot uploadImgByHttpEndpoint CommonController.java HttpFileToMultipartFileUtil.downloadImageData server-side request forgery CWE-918 6.3 Medium2026-05-02
CVE-2026-7604 JeecgBoot OpenApi Service OpenApiController.java OpenApiController.call server-side request forgery CWE-918 6.3 Medium2026-05-02
CVE-2026-7603 JeecgBoot LoadFile Endpoint FileDownloadUtils.jav checkPathTraversalBatch server-side request forgery CWE-918 6.3 Medium2026-05-02
CVE-2026-7602 JeecgBoot FillRuleUtil edit improper authorization CWE-285 6.3 Medium2026-05-02
CVE-2026-7290 JeecgBoot loadDict Endpoint SqlInjectionUtil.java SqlInjectionUtil sql injection CWE-89 6.3 Medium2026-04-28
CVE-2026-5999 JeecgBoot SysAnnouncementController improper authorization CWE-285 6.3 Medium2026-04-10
CVE-2026-5616 JeecgBoot AI Chat JeecgBizToolsProvider.java missing authentication CWE-306 7.3 High2026-04-06
CVE-2026-3672 JeecgBoot getDictItems isExistSqlInjectKeyword sql injection CWE-89 6.3 Medium2026-03-07
CVE-2026-2945 JeecgBoot uploadImgByHttp server-side request forgery CWE-918 6.3 Medium2026-02-22
CVE-2026-2822 JeecgBoot Backend airag_app,1,create_by sql injection CWE-89 6.3 Medium2026-02-20
CVE-2026-2555 JeecgBoot Retrieval-Augmented Generation AiragKnowledgeController.java importDocumentFromZip deserialization CWE-502 5.0 Medium2026-02-16
CVE-2026-2111 JeecgBoot Retrieval-Augmented Generation edit path traversal CWE-22 4.3 Medium2026-02-07
CVE-2026-1746 JeecgBoot Online Report API loadDictItemByKeyword sql injection CWE-89 6.3 Medium2026-02-02
CVE-2025-15126 JeecgBoot getPositionUserList improper authorization CWE-285 3.1 Low2025-12-28
CVE-2025-15125 JeecgBoot queryDepartPermission improper authorization CWE-285 3.1 Low2025-12-28
CVE-2025-15124 JeecgBoot list getParameterMap improper authorization CWE-285 3.1 Low2025-12-28

All 47 known CVE vulnerabilities affecting JeecgBoot with full Chinese analysis, references, and POCs where available.