Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

jishenghua — Vulnerabilities & Security Advisories 16

Browse all 16 CVE security advisories affecting jishenghua. AI-powered Chinese analysis, POCs, and references for each vulnerability.

This page aggregates security vulnerability records for the vendor jishenghua, focusing on reported software weaknesses and security flaws within their products. It collects known issues including buffer overflows, input validation errors, and authentication bypasses, covering a timeline from initial disclosure through recent patches. Readers can utilize this resource to track the vendor’s security advisories, understand specific weakness classes affecting their software, or review the historical vulnerability landscape of individual products to assess current risk exposure. The data is organized to facilitate technical analysis, allowing security teams to identify patterns in jishenghua’s security posture over time. By examining these aggregated entries, stakeholders can determine the frequency and severity of past incidents, helping to inform future security audits and remediation priorities. This summary serves as a reference point for evaluating the overall stability and security maturity of jishenghua solutions within enterprise environments.

Top products by jishenghua: jshERP
CVE ID Title CVSS Severity Published
CVE-2026-105621 jishenghua jshERP Financial Receipt Update AccountHeadService.java updateAccountHeadAndDetail improper authorization — jshERP CWE-285 5.4 Medium 2026-10-06
CVE-2026-94501 jshERP through 3.6 Privilege Escalation via userBusiness CRUD — jshERP CWE-862 8.8 High 2026-09-21
CVE-2026-94497 jshERP through 3.6 Unauthorized Access via by-id Endpoints — jshERP CWE-639 8.3 High 2026-09-21
CVE-2026-94496 jshERP through 3.6 Privilege Escalation via Role Management — jshERP CWE-862 8.3 High 2026-09-21
CVE-2026-94495 jshERP through 3.6 Missing Authorization via systemConfig — jshERP CWE-862 7.1 High 2026-09-21
CVE-2026-94494 jshERP through 3.6 Tenant Information Disclosure via GET /tenant/info — jshERP CWE-639 5.0 Medium 2026-09-21
CVE-2026-94414 jshERP through 3.6 Missing Authorization via updateBtnStr — jshERP CWE-862 5.4 Medium 2026-09-21
CVE-2026-94413 jshERP through 3.6 Password Hash Disclosure via /user/info — jshERP CWE-200 6.5 Medium 2026-09-21
CVE-2026-94412 jshERP through 3.6 Authorization Bypass via resetPwd — jshERP CWE-862 8.8 High 2026-09-21
CVE-2026-94411 jshERP 3.6 Privilege Escalation via updateOneValueByKeyIdAndType — jshERP CWE-862 8.8 High 2026-09-21
CVE-2026-11469 jishenghua jshERP platformConfig Add Endpoint PlatformConfigService.java insertPlatformConfig server-side request forgery — jshERP CWE-918 4.7 Medium 2026-06-07
CVE-2026-11467 jishenghua jshERP addAccountHeadAndDetail Endpoint AccountHeadService.java path traversal — jshERP CWE-22 5.4 Medium 2026-06-07
CVE-2026-8320 jishenghua jshERP updatePlatformConfigByKey Endpoint UserService.java getUserByWeixinCode server-side request forgery — jshERP CWE-918 4.7 Medium 2026-05-11
CVE-2026-1588 jishenghua jshERP installByPath install path traversal — jshERP CWE-22 2.7 Low 2026-01-29
CVE-2026-1549 jishenghua jshERP PluginController uploadPluginConfigFile path traversal — jshERP CWE-22 4.3 Medium 2026-01-28
CVE-2026-1546 jishenghua jshERP com.jsh.erp.datasource.mappers.DepotItemMapperEx importItemExcel getBillItemByParam sql injection — jshERP CWE-89 6.3 Medium 2026-01-28

This page lists every published CVE security advisory associated with jishenghua. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.