JeecgBoot是中国国炬(Jeecg)公司的一个适用于企业 Web 应用程序的 Java 低代码平台。 JeecgBoot 3.9.1及之前版本存在注入漏洞,该漏洞源于JSON对象处理器中文件/sys/dict/loadTreeData的参数condition的操作,可能导致SQL注入攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | JeecgBoot | 3.9.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-36458 | ChestnutCMS 安全漏洞 | |
| CVE-2026-30496 | Optoma CinemaX P2 安全漏洞 | |
| CVE-2026-30495 | Optoma CinemaX P2 安全漏洞 | |
| CVE-2025-67202 | sidekiq-cron 安全漏洞 | |
| CVE-2025-63706 | next-npm-version 1.0.1 安全漏洞 | |
| CVE-2025-63705 | Node Typescript OCR 安全漏洞 | |
| CVE-2026-36387 | CodeAstro Membership Management System 代码问题漏洞 | |
| CVE-2026-36388 | PHPGurukul Hospital Management System 跨站脚本漏洞 | |
| CVE-2025-65122 | youtube-regex 资源管理错误漏洞 | |
| CVE-2026-36341 | Webkul Krayin CRM 跨站脚本漏洞 | |
| CVE-2025-63704 | Query String Parser 安全漏洞 | |
| CVE-2025-63703 | parse-ini 安全漏洞 | |
| CVE-2026-37709 | Snipe-IT 访问控制错误漏洞 |
No comments yet