Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

JeecgBoot — Vulnerabilities & Security Advisories 46

All 46 CVE vulnerabilities found in JeecgBoot, with AI-generated Chinese analysis, references, and POCs.

This page catalogs known security vulnerabilities and weaknesses associated with the JeecgBoot open-source development platform. It focuses on aggregate data related to common weakness types, such as injection flaws, cross-site scripting, and insecure configurations, providing a centralized view of the product's security posture. The content collected on this page includes documented defects reported by security researchers, developers, and third-party auditors, covering a comprehensive historical time range that reflects both past patches and currently unaddressed risks. By reviewing this aggregated information, users can effectively track vendor advisories and official responses to emerging threats, gaining insight into how the JeecgBoot team handles security incidents over time. Additionally, the page allows for a deeper understanding of specific weakness classes that frequently impact this framework, helping developers identify patterns in code vulnerabilities. Readers can also look up the complete vulnerability history of JeecgBoot to assess long-term stability and the frequency of security updates, facilitating informed decisions regarding platform adoption and maintenance. This resource serves as a factual reference point for security professionals and IT administrators seeking to evaluate the risk profile of JeecgBoot in enterprise environments. It does not offer subjective opinions or promotional material, but rather presents verified data points that contribute to a holistic understanding of the software's security landscape.

Vendor: n/a

CVE IDTitleCVSSSeverityPublished
CVE-2025-15122 JeecgBoot datarule loadDatarule improper authorization CWE-285 3.1 Low2025-12-28
CVE-2025-15121 JeecgBoot getDeptRoleByUserId information disclosure CWE-200 2.4 Low2025-12-28
CVE-2025-15120 JeecgBoot getDeptRoleList improper authorization CWE-285 3.1 Low2025-12-28
CVE-2025-15119 JeecgBoot list queryPageList improper authorization CWE-285 3.1 Low2025-12-28
CVE-2025-14909 JeecgBoot SysUserOnlineController.java SysUserOnlineController user session CWE-1018 4.3 Medium2025-12-19
CVE-2025-14908 JeecgBoot Multi-Tenant Management SysTenantController.java improper authentication CWE-287 6.3 Medium2025-12-19
CVE-2025-10981 JeecgBoot exportXls improper authorization CWE-285 4.3 Medium2025-09-26
CVE-2025-10980 JeecgBoot exportXls improper authorization CWE-285 4.3 Medium2025-09-25
CVE-2025-10979 JeecgBoot exportXls improper authorization CWE-285 4.3 Medium2025-09-25
CVE-2025-10978 JeecgBoot Filter exportXls improper authorization CWE-285 4.3 Medium2025-09-25
CVE-2025-10977 JeecgBoot deleteBatch improper authorization CWE-285 3.1 Low2025-09-25
CVE-2025-10976 JeecgBoot getDepartUserList improper authorization CWE-285 3.1 Low2025-09-25
CVE-2025-10707 JeecgBoot sendMsg improper authorization CWE-285 6.3 Medium2025-09-19
CVE-2025-10319 JeecgBoot Tenant Log Export exportLog improper authorization CWE-285 4.3 Medium2025-09-12
CVE-2025-10318 JeecgBoot WebSocket Message sendWebSocketMsg improper authorization CWE-285 6.3 Medium2025-09-12
CVE-2025-4533 JeecgBoot Document Library Upload zip unzipFile resource consumption CWE-400 2.7 Low2025-05-11

All 46 known CVE vulnerabilities affecting JeecgBoot with full Chinese analysis, references, and POCs where available.