Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Jinher — Vulnerabilities & Security Advisories 18

Browse all 18 CVE security advisories affecting Jinher. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Jinher develops enterprise software solutions, primarily focusing on office automation and digital government platforms. Historically, their products have been susceptible to multiple remote code execution vulnerabilities, cross-site scripting flaws, and privilege escalation issues. The company's security posture has been marked by inconsistent patch management, with several critical vulnerabilities remaining unaddressed for extended periods. Notable incidents include a 2021 vulnerability assessment that identified over a dozen CVEs, many allowing complete system compromise. Security researchers have frequently criticized the slow response times to reported vulnerabilities, leaving enterprise deployments at elevated risk despite the software's widespread adoption in public sector environments.

Top products by Jinher: OA OA C6
CVE ID Title CVSS Severity Published
CVE-2026-19905 Jinher OA attendance_out_approve.aspx sql injection — OA CWE-89 7.3 High 2026-08-15
CVE-2026-15517 Jinher OA PlanGiveOut.aspx sql injection — OA CWE-89 7.3 High 2026-07-13
CVE-2026-11435 Jinher OA nextselectplan.aspx sql injection — OA CWE-89 7.3 High 2026-06-06
CVE-2026-11412 Jinher OA GetFormSn.aspx sql injection — OA CWE-89 6.3 Medium 2026-06-06
CVE-2026-7670 Jinher OA UserSel.aspx sql injection — OA CWE-89 7.3 High 2026-05-02
CVE-2026-2963 Jinher OA C6 OfficeSupplyTypeRight.aspx sql injection — OA C6 CWE-89 6.3 Medium 2026-02-23
CVE-2025-11341 Jinher OA type xml external entity reference — OA CWE-611 7.3 High 2025-10-06
CVE-2025-11035 Jinher OA text xml external entity reference — OA CWE-611 6.3 Medium 2025-09-26
CVE-2025-10816 Jinher OA XML text xml external entity reference — OA CWE-611 7.3 High 2025-09-22
CVE-2025-10092 Jinher OA XML Type xml external entity reference — OA CWE-611 7.3 High 2025-09-08
CVE-2025-10091 Jinher OA XML Type xml external entity reference — OA CWE-611 7.3 High 2025-09-08
CVE-2025-10090 Jinher OA GetTreeDate.aspx sql injection — OA CWE-89 7.3 High 2025-09-08
CVE-2025-9931 Jinher OA POST Request login!changePassWord.action cross site scripting — OA CWE-79 4.3 Medium 2025-09-03
CVE-2025-9669 Jinher OA GetTreeDate.aspx sql injection — OA CWE-89 7.3 High 2025-08-29
CVE-2025-7824 Jinher OA XmlHttp.aspx xml external entity reference — OA CWE-611 7.3 High 2025-07-19
CVE-2025-7823 Jinher OA ProjectScheduleDelete.aspx xml external entity reference — OA CWE-611 7.3 High 2025-07-19
CVE-2025-7523 Jinher OA DelTemp.aspx xml external entity reference — OA CWE-611 7.3 High 2025-07-13
CVE-2025-2587 Jinher OA C6 IncentivePlanFulfillAppprove.aspx sql injection — OA C6 CWE-89 6.3 Medium 2025-03-21

This page lists every published CVE security advisory associated with Jinher. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.