ZeroHour

Vulnerabilities

73 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-43028
+1 in the same advisory: …40489
A command injection vulnerability in the component /jmreport/show of jeecg boot v3.0.0 to v3.5.3 allows attackers to execute arbitrary code via a crafted HTTP r

A command injection vulnerability in the component /jmreport/show of jeecg boot v3.0.0 to v3.5.3 allows attackers to execute arbitrary code via a crafted HTTP request.

NVD description · AI analysis pending
9.82%
  • jeecg jeecg boot
CVE-2026-2945
A weakness has been identified in JeecgBoot 3.9.0.

A weakness has been identified in JeecgBoot 3.9.0. Affected by this vulnerability is an unknown functionality of the file /sys/common/uploadImgByHttp. Executing a manipulation of the argument fileUrl can lead to server-side request forgery. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

NVD description · AI analysis pending
2.1<1% PoC
  • jeecg jeecg boot
CVE-2026-2822
A security vulnerability has been detected in JeecgBoot up to 3.9.1.

A security vulnerability has been detected in JeecgBoot up to 3.9.1. The affected element is an unknown function of the file /jeecgboot/sys/dict/loadDict/airag_app,1,create_by of the component Backend Interface. Such manipulation of the argument keyword leads to sql injection. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.

NVD description · AI analysis pending
2.1<1% PoC
  • jeecg jeecg boot
CVE-2026-2555
A weakness has been identified in JeecgBoot 3.9.1.

A weakness has been identified in JeecgBoot 3.9.1. This vulnerability affects the function importDocumentFromZip of the file org/jeecg/modules/airag/llm/controller/AiragKnowledgeController.java of the component Retrieval-Augmented Generation. Executing a manipulation can lead to deserialization. The attack can be launched remotely. Attacks of this nature are highly complex. It is stated that the exploitability is difficult. The project was informed of the problem early through an issue report but has not responded yet.

NVD description · AI analysis pending
2.3<1% PoC
  • jeecg jeecg boot
CVE-2026-2111
A weakness has been identified in JeecgBoot up to 3.9.0.

A weakness has been identified in JeecgBoot up to 3.9.0. Affected by this issue is some unknown functionality of the file /airag/knowledge/doc/edit of the component Retrieval-Augmented Generation Module. Executing a manipulation of the argument filePath can lead to path traversal. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

NVD description · AI analysis pending
2.1<1% PoC
  • jeecg jeecg boot
CVE-2026-1746
A vulnerability was identified in JeecgBoot 3.9.0.

A vulnerability was identified in JeecgBoot 3.9.0. This vulnerability affects unknown code of the file /JeecgBoot/sys/api/loadDictItemByKeyword of the component Online Report API. Such manipulation of the argument keyword leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

NVD description · AI analysis pending
2.1<1% PoC
  • jeecg jeecg boot
CVE-2025-66913
JimuReport thru version 2.1.3 is vulnerable to remote code execution when processing user-controlled H2 JDBC URLs.

JimuReport thru version 2.1.3 is vulnerable to remote code execution when processing user-controlled H2 JDBC URLs. The application passes the attacker-supplied JDBC URL directly to the H2 driver, allowing the use of certain directives to execute arbitrary Java code. A different vulnerability than CVE-2025-10770.

NVD description · AI analysis pending
9.81% PoC
  • jeecg jimureport
CVE-2025-15121
A vulnerability has been found in JeecgBoot up to 3.9.0.

A vulnerability has been found in JeecgBoot up to 3.9.0. The affected element is the function getDeptRoleByUserId of the file /sys/sysDepartRole/getDeptRoleByUserId. Such manipulation of the argument departId leads to information disclosure. The vendor was contacted early about this disclosure but did not respond in any way.

NVD description · AI analysis pending
4.8
group max
<1% PoC ×2
  • jeecg jeecg boot
CVE-2025-14909
+1 in the same advisory: …14908
A weakness has been identified in JeecgBoot up to 3.9.0.

A weakness has been identified in JeecgBoot up to 3.9.0. The impacted element is the function SysUserOnlineController of the file jeecg-boot/jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/system/controller/SysUserOnlineController.java. Executing manipulation can lead to manage user sessions. The attack can be launched remotely. The exploit has been made available to the public and could be exploited. This patch is called b686f9fbd1917edffe5922c6362c817a9361cfbd. Applying a patch is advised to resolve this issue.

NVD description · AI analysis pending
2.1<1% PoC ×3
  • jeecg jeecg boot
CVE-2025-61189
+1 in the same advisory: …61188
Jeecgboot versions 3.8.2 and earlier are affected by a path traversal vulnerability.

Jeecgboot versions 3.8.2 and earlier are affected by a path traversal vulnerability. The endpoint is /sys/comment/addFile. This vulnerability allows attackers to upload files with system-whitelisted extensions to the system directory /opt, instead of the /opt/upFiles directory specified by the web server.

NVD description · AI analysis pending
6.3<1% PoC
  • jeecg jeecg boot
CVE-2025-10980
+1 in the same advisory: …10981
A security vulnerability has been detected in JeecgBoot up to 3.8.2.

A security vulnerability has been detected in JeecgBoot up to 3.8.2. This affects an unknown function of the file /sys/position/exportXls. Such manipulation leads to improper authorization. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

NVD description · AI analysis pending
2.1<1% PoC
  • jeecg jeecg boot
CVE-2025-10979
+3 in the same advisory: …10978 …10977 …10976
A weakness has been identified in JeecgBoot up to 3.8.2.

A weakness has been identified in JeecgBoot up to 3.8.2. The impacted element is an unknown function of the file /sys/role/exportXls. This manipulation causes improper authorization. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be exploited. The vendor was contacted early about this disclosure but did not respond in any way.

NVD description · AI analysis pending
2.1
group max
<1% PoC
  • jeecg jeecg boot
CVE-2025-10771
+1 in the same advisory: …10770
A vulnerability was determined in jeecgboot JimuReport up to 2.1.2.

A vulnerability was determined in jeecgboot JimuReport up to 2.1.2. Affected is an unknown function of the file /drag/onlDragDataSource/testConnection of the component DB2 JDBC Handler. Executing manipulation of the argument clientRerouteServerListJNDIName can lead to deserialization. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized.

NVD description · AI analysis pending
2.1<1% PoC ×2
  • jeecg jimureport
CVE-2025-10707
A weakness has been identified in JeecgBoot up to 3.8.2.

A weakness has been identified in JeecgBoot up to 3.8.2. Affected is an unknown function of the file /message/sysMessageTemplate/sendMsg. Executing manipulation can lead to improper authorization. The attack may be launched remotely. The exploit has been made available to the public and could be exploited. The vendor was contacted early about this disclosure but did not respond in any way.

NVD description · AI analysis pending
2.1<1% PoC
  • jeecg jeecg boot
CVE-2025-10318
+1 in the same advisory: …10319
A vulnerability was identified in JeecgBoot up to 3.8.2.

A vulnerability was identified in JeecgBoot up to 3.8.2. Affected by this vulnerability is an unknown functionality of the file /api/system/sendWebSocketMsg of the component WebSocket Message Handler. The manipulation of the argument userIds leads to improper authorization. The attack can be initiated remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

NVD description · AI analysis pending
2.1<1% PoC
  • jeecg jeecg boot
CVE-2025-8963
A vulnerability was determined in jeecgboot JimuReport up to 2.1.1.

A vulnerability was determined in jeecgboot JimuReport up to 2.1.1. Affected by this issue is some unknown functionality of the file /drag/onlDragDataSource/testConnection of the component Data Large Screen Template. The manipulation leads to deserialization. The attack may be launched remotely. The vendor response to the GitHub issue report is: "Modified, next version updated".

NVD description · AI analysis pending
5.3<1% PoC
  • jeecg jimureport
CVE-2025-4533
A vulnerability classified as problematic was found in JeecgBoot up to 3.8.0.

A vulnerability classified as problematic was found in JeecgBoot up to 3.8.0. This vulnerability affects the function unzipFile of the file /jeecg-boot/airag/knowledge/doc/import/zip of the component Document Library Upload. The manipulation of the argument File leads to resource consumption. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

NVD description · AI analysis pending
5.1<1% PoC ×3
  • jeecg jeecg boot
CVE-2024-48307
Unauthenticated SQL Injection in JeecgBoot 3.7.1 getTotalData Endpoint

CVE-2024-48307 is a SQL injection vulnerability (CWE-89) in JeecgBoot v3.7.1, an open-source Java-based low-code platform, reachable through the /onlDragDatasetHead/getTotalData component. An attacker can send crafted input to parameters consumed by that endpoint over the network; the CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N) indicates exploitation requires no privileges, no user interaction, and low attack complexity. Successful injection can allow arbitrary SQL execution against the backend database, enabling theft or tampering of application data, with impact potentially limited by the database account's privileges. Any organization running JeecgBoot 3.7.1 is affected, particularly instances exposed to the internet or to untrusted users. There is no confirmed in-the-wild exploitation yet: a public PoC/reference exists (GitHub issue #7237), the flaw is not in CISA KEV, but its high EPSS score (44.3% probability of exploitation within 30 days, 99th percentile) signals an elevated near-term exploitation risk.

Do: Upgrade JeecgBoot from 3.7.1 to the latest patched release per the vendor's GitHub advisories/releases (no fixed version is specified in the available data). Until patched, restrict or filter access to /onlDragDatasetHead/getTotalData at a reverse proxy or WAF, enforce authentication on that route if not already required, and monitor logs for SQL injection payloads targeting it. Internet-exposed JeecgBoot instances should be prioritized for patching given the elevated EPSS score.

9.844% PoC
  • JeecgBoot 3.7.1 (version reported as containing the flaw; no broader version range specified in the data)
large≈10,000–100,000 deployments (popular self-hosted low-code platform; exact install counts unpublished)
CVE-2024-44893
An issue in the component /jeecg-boot/jmreport/dict/list of JimuReport v1.7.8 allows attacker to escalate privileges via a crafted GET request.

An issue in the component /jeecg-boot/jmreport/dict/list of JimuReport v1.7.8 allows attacker to escalate privileges via a crafted GET request.

NVD description · AI analysis pending
9.8<1% PoC
  • jeecg jimureport
CVE-2023-49442
Deserialization of Untrusted Data in jeecgFormDemoController in JEECG 4.0 and earlier allows attackers to run arbitrary code via crafted POST request.

Deserialization of Untrusted Data in jeecgFormDemoController in JEECG 4.0 and earlier allows attackers to run arbitrary code via crafted POST request.

NVD description · AI analysis pending
9.839%
  • jeecg jeecg
CVE-2023-41544
+2 in the same advisory: …41543 …41542
SSTI injection vulnerability in jeecg-boot version 3.5.3, allows remote attackers to execute arbitrary code via crafted HTTP request to the /jmreport/loadTableD

SSTI injection vulnerability in jeecg-boot version 3.5.3, allows remote attackers to execute arbitrary code via crafted HTTP request to the /jmreport/loadTableData component.

NVD description · AI analysis pending
9.83% PoC
  • jeecg jeecg boot
CVE-2023-6307
A vulnerability classified as critical was found in jeecgboot JimuReport up to 1.6.1.

A vulnerability classified as critical was found in jeecgboot JimuReport up to 1.6.1. Affected by this vulnerability is an unknown functionality of the file /download/image. The manipulation of the argument imageUrl leads to relative path traversal. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-246133 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

NVD description · AI analysis pending
9.8<1%
  • jeecg jimureport
CVE-2023-47467
Directory Traversal vulnerability in jeecg-boot v.3.6.0 allows a remote privileged attacker to obtain sensitive information via the file directory structure.

Directory Traversal vulnerability in jeecg-boot v.3.6.0 allows a remote privileged attacker to obtain sensitive information via the file directory structure.

NVD description · AI analysis pending
6.51%
  • jeecg jeecg boot
CVE-2023-40989
SQL injection vulnerbility in jeecgboot jeecg-boot v 3.0, 3.5.3 that allows a remote attacker to execute arbitrary code via a crafted request to the report/jeec

SQL injection vulnerbility in jeecgboot jeecg-boot v 3.0, 3.5.3 that allows a remote attacker to execute arbitrary code via a crafted request to the report/jeecgboot/jmreport/queryFieldBySql component.

NVD description · AI analysis pending
9.82%
  • jeecg jeecg boot
CVE-2023-42268
+1 in the same advisory: …41578
Jeecg boot up to v3.5.3 was discovered to contain a SQL injection vulnerability via the component /jeecg-boot/jmreport/show.

Jeecg boot up to v3.5.3 was discovered to contain a SQL injection vulnerability via the component /jeecg-boot/jmreport/show.

NVD description · AI analysis pending
9.8
group max
<1% PoC
  • jeecg jeecg boot
CVE-2023-4450
A vulnerability was found in jeecgboot JimuReport up to 1.6.0.

A vulnerability was found in jeecgboot JimuReport up to 1.6.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Template Handler. The manipulation leads to injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.6.1 is able to address this issue. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-237571.

NVD description · AI analysis pending
9.812%
  • jeecg jimureport
CVE-2023-38905
SQL injection vulnerability in Jeecg-boot v.3.5.0 and before allows a local attacker to cause a denial of service via the Benchmark, PG_Sleep, DBMS_Lock.Sleep,

SQL injection vulnerability in Jeecg-boot v.3.5.0 and before allows a local attacker to cause a denial of service via the Benchmark, PG_Sleep, DBMS_Lock.Sleep, Waitfor, DECODE, and DBMS_PIPE.RECEIVE_MESSAGE functions.

NVD description · AI analysis pending
5.5<1% PoC ×2
  • jeecg jeecg boot
CVE-2023-38992
jeecg-boot v3.5.1 was discovered to contain a SQL injection vulnerability via the title parameter at /sys/dict/loadTreeData.

jeecg-boot v3.5.1 was discovered to contain a SQL injection vulnerability via the title parameter at /sys/dict/loadTreeData.

NVD description · AI analysis pending
9.873% PoC
  • jeecg jeecg boot
CVE-2023-34602
+1 in the same advisory: …34603
JeecgBoot up to v 3.5.1 was discovered to contain a SQL injection vulnerability via the component queryTableDictItemsByCode at org.jeecg.modules.api.controller.

JeecgBoot up to v 3.5.1 was discovered to contain a SQL injection vulnerability via the component queryTableDictItemsByCode at org.jeecg.modules.api.controller.SystemApiController.

NVD description · AI analysis pending
7.5<1% PoC
  • jeecg jeecgboot
CVE-2023-34660
jjeecg-boot V3.5.0 has an unauthorized arbitrary file upload in /jeecg-boot/jmreport/upload interface.

jjeecg-boot V3.5.0 has an unauthorized arbitrary file upload in /jeecg-boot/jmreport/upload interface.

NVD description · AI analysis pending
6.5<1% PoC
  • jeecg jeecg boot