Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

jeecgboot — Vulnerabilities & Security Advisories 11

Browse all 11 CVE security advisories affecting jeecgboot. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Jeecgboot is a low-code development platform primarily used for building enterprise applications. Historically, it has been vulnerable to multiple security issues including remote code execution (RCE), cross-site scripting (XSS), and privilege escalation vulnerabilities. The platform's CVE history shows consistent patterns of authentication bypass flaws and insufficient input validation. Jeecgboot has faced several critical security incidents, with its most recent vulnerabilities involving unsafe deserialization and improper access controls. Despite these issues, the platform remains popular in enterprise environments due to its rapid development capabilities, though organizations should implement strict security controls when deploying it.

CVE IDTitleCVSSSeverityPublished
CVE-2026-75479 JimuReport Unauthenticated Report Listing and Share Token Disclosure — jimureportCWE-306 7.5 High2026-08-17
CVE-2026-58377 JeecgBoot 3.9.2 - Missing Authorization on OpenAPI Credential Management Endpoints Exposes Access/Secret Keys — JeecgBootCWE-862 8.1 High2026-06-30
CVE-2026-58375 JimuReport 2.5.0 - Unauthenticated Report Export via /jmreport/auto/export — jimureportCWE-306 7.5 High2026-06-30
CVE-2026-10241 jeecgboot The server processes these URLs Cloud Instance Metadata Endpoint debug FileDownloadUtils.download2DiskFromNet server-side request forgery — The server processes these URLsCWE-918 6.3 Medium2026-06-01
CVE-2026-5848 jeecgboot JimuReport Data Source testConnection DriverManager.getConnection code injection — JimuReportCWE-94 4.7 Medium2026-04-09
CVE-2025-12626 jeecgboot jeewx-boot WxActGoldeneggsPrizesController.java getImgUrl path traversal — jeewx-bootCWE-22 4.3 Medium2025-11-03
CVE-2025-10771 jeecgboot JimuReport DB2 JDBC testConnection deserialization — JimuReportCWE-502 6.3 Medium2025-09-21
CVE-2025-10770 jeecgboot JimuReport MySQL JDBC testConnection deserialization — JimuReportCWE-502 6.3 Medium2025-09-21
CVE-2025-8963 jeecgboot JimuReport Data Large Screen Template testConnection deserialization — JimuReportCWE-502 6.3 Medium2025-08-14
CVE-2023-6307 jeecgboot JimuReport image path traversal — JimuReportCWE-23 6.3 Medium2023-11-27
CVE-2023-4450 jeecgboot JimuReport Template injection — JimuReportCWE-74 6.3 Medium2023-08-21

This page lists every published CVE security advisory associated with jeecgboot. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.