Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

jeecgboot — Vulnerabilities & Security Advisories 12

Browse all 12 CVE security advisories affecting jeecgboot. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Jeecgboot is a low-code development platform primarily used for building enterprise applications. Historically, it has been vulnerable to multiple security issues including remote code execution (RCE), cross-site scripting (XSS), and privilege escalation vulnerabilities. The platform's CVE history shows consistent patterns of authentication bypass flaws and insufficient input validation. Jeecgboot has faced several critical security incidents, with its most recent vulnerabilities involving unsafe deserialization and improper access controls. Despite these issues, the platform remains popular in enterprise environments due to its rapid development capabilities, though organizations should implement strict security controls when deploying it.

CVE ID Title CVSS Severity Published
CVE-2026-82629 jeecgboot jeewx-boot doUpload Endpoint MyJwWebJwid3Controller.java MyJwWebJwid3Controller.doUpload unrestricted upload — jeewx-boot CWE-434 4.7 Medium 2026-08-31
CVE-2026-75479 JimuReport Unauthenticated Report Listing and Share Token Disclosure — jimureport CWE-306 7.5 High 2026-08-17
CVE-2026-58377 JeecgBoot 3.9.2 - Missing Authorization on OpenAPI Credential Management Endpoints Exposes Access/Secret Keys — JeecgBoot CWE-862 8.1 High 2026-06-30
CVE-2026-58375 JimuReport 2.5.0 - Unauthenticated Report Export via /jmreport/auto/export — jimureport CWE-306 7.5 High 2026-06-30
CVE-2026-10241 jeecgboot The server processes these URLs Cloud Instance Metadata Endpoint debug FileDownloadUtils.download2DiskFromNet server-side request forgery — The server processes these URLs CWE-918 6.3 Medium 2026-06-01
CVE-2026-5848 jeecgboot JimuReport Data Source testConnection DriverManager.getConnection code injection — JimuReport CWE-94 4.7 Medium 2026-04-09
CVE-2025-12626 jeecgboot jeewx-boot WxActGoldeneggsPrizesController.java getImgUrl path traversal — jeewx-boot CWE-22 4.3 Medium 2025-11-03
CVE-2025-10771 jeecgboot JimuReport DB2 JDBC testConnection deserialization — JimuReport CWE-502 6.3 Medium 2025-09-21
CVE-2025-10770 jeecgboot JimuReport MySQL JDBC testConnection deserialization — JimuReport CWE-502 6.3 Medium 2025-09-21
CVE-2025-8963 jeecgboot JimuReport Data Large Screen Template testConnection deserialization — JimuReport CWE-502 6.3 Medium 2025-08-14
CVE-2023-6307 jeecgboot JimuReport image path traversal — JimuReport CWE-23 6.3 Medium 2023-11-27
CVE-2023-4450 jeecgboot JimuReport Template injection — JimuReport CWE-74 6.3 Medium 2023-08-21

This page lists every published CVE security advisory associated with jeecgboot. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.