| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-5999 | JeecgBoot SysAnnouncementController improper authorization | - | JeecgBoot | Medium | 6.3 | 2026-04-10 01:45:14 | Deep Dive |
| CVE-2026-5848 | jeecgboot JimuReport Data Source testConnection DriverManager.getConnection code injection | jeecgboot | JimuReport | Medium | 4.7 | 2026-04-09 05:15:11 | Deep Dive |
| CVE-2026-5616 | JeecgBoot AI Chat JeecgBizToolsProvider.java missing authentication | - | JeecgBoot | High | 7.3 | 2026-04-06 03:15:15 | Deep Dive |
| CVE-2026-3672 | JeecgBoot getDictItems isExistSqlInjectKeyword sql injection | - | JeecgBoot | Medium | 6.3 | 2026-03-07 21:32:13 | Deep Dive |
| CVE-2026-2945 | JeecgBoot uploadImgByHttp server-side request forgery | - | JeecgBoot | Medium | 6.3 | 2026-02-22 13:02:13 | Deep Dive |
| CVE-2026-2822 | JeecgBoot Backend airag_app,1,create_by sql injection | - | JeecgBoot | Medium | 6.3 | 2026-02-20 04:32:11 | Deep Dive |
| CVE-2026-2555 | JeecgBoot Retrieval-Augmented Generation AiragKnowledgeController.java importDocumentFromZip deserialization | - | JeecgBoot | Medium | 5.0 | 2026-02-16 12:02:07 | Deep Dive |
| CVE-2026-2111 | JeecgBoot Retrieval-Augmented Generation edit path traversal | - | JeecgBoot | Medium | 4.3 | 2026-02-07 20:32:09 | Deep Dive |
| CVE-2026-1746 | JeecgBoot Online Report API loadDictItemByKeyword sql injection | - | JeecgBoot | Medium | 6.3 | 2026-02-02 05:32:11 | Deep Dive |
| CVE-2025-15126 | JeecgBoot getPositionUserList improper authorization | - | JeecgBoot | Low | 3.1 | 2025-12-28 07:32:06 | Deep Dive |
| CVE-2025-15125 | JeecgBoot queryDepartPermission improper authorization | - | JeecgBoot | Low | 3.1 | 2025-12-28 07:02:07 | Deep Dive |
| CVE-2025-15124 | JeecgBoot list getParameterMap improper authorization | - | JeecgBoot | Low | 3.1 | 2025-12-28 06:32:07 | Deep Dive |
| CVE-2025-15123 | JeecgBoot datarule improper authorization | - | JeecgBoot | Low | 3.1 | 2025-12-28 06:02:06 | Deep Dive |
| CVE-2025-15122 | JeecgBoot datarule loadDatarule improper authorization | - | JeecgBoot | Low | 3.1 | 2025-12-28 05:02:06 | Deep Dive |
| CVE-2025-15121 | JeecgBoot getDeptRoleByUserId information disclosure | - | JeecgBoot | Low | 2.4 | 2025-12-28 04:32:06 | Deep Dive |
| CVE-2025-15120 | JeecgBoot getDeptRoleList improper authorization | - | JeecgBoot | Low | 3.1 | 2025-12-28 04:02:06 | Deep Dive |
| CVE-2025-15119 | JeecgBoot list queryPageList improper authorization | - | JeecgBoot | Low | 3.1 | 2025-12-28 03:32:07 | Deep Dive |
| CVE-2025-14909 | JeecgBoot SysUserOnlineController.java SysUserOnlineController user session | - | JeecgBoot | Medium | 4.3 | 2025-12-19 01:02:08 | Deep Dive |
| CVE-2025-14908 | JeecgBoot Multi-Tenant Management SysTenantController.java improper authentication | - | JeecgBoot | Medium | 6.3 | 2025-12-19 00:32:08 | Deep Dive |
| CVE-2025-12626 | jeecgboot jeewx-boot WxActGoldeneggsPrizesController.java getImgUrl path traversal | jeecgboot | jeewx-boot | Medium | 4.3 | 2025-11-03 13:02:06 | Deep Dive |