Jeecgboot
This hub aggregates every CVE we track for Jeecgboot, a product in the enterprise software space. Use it to gauge the current risk picture and drill into individual advisories.
6
CVEs tracked
1
Critical
4
High
0
In CISA KEV
Severity distribution
HIGH4MEDIUM1CRITICAL1
Monthly trend
0
0
0
0
1
0
0
0
0
0
1
0
0
0
0
0
0
0
0
0
1
0
0
0
2024-102026-09
Latest CVEs
The 6 most recently published vulnerabilities affecting Jeecgboot.
- CVE-2026-58377JeecgBoot 3.9.2 - Missing Authorization on OpenAPI Credential Management Endpoints Exposes Access/Secret Keys8.1
- CVE-2025-51825JeecgBoot versions from 3.4.3 up to 3.8.0 were found to contain a SQL injection vulnerability in the /jeecg-boot/online/cgreport/head/parseSql endpoint, which allows bypassing SQL blacklist restric...6.5
- CVE-2024-57606SQL injection vulnerability in Beijing Guoju Information Technology Co., Ltd JeecgBoot v.3.7.2 allows a remote attacker to obtain sensitive information via the getTotalData component.7.5
- CVE-2023-34603JeecgBoot up to v 3.5.1 was discovered to contain a SQL injection vulnerability via the component queryFilterTableDictInfo at org.jeecg.modules.api.controller.SystemApiController.7.5
- CVE-2023-34602JeecgBoot up to v 3.5.1 was discovered to contain a SQL injection vulnerability via the component queryTableDictItemsByCode at org.jeecg.modules.api.controller.SystemApiController.7.5
- CVE-2023-34659jeecg-boot 3.5.0 and 3.5.1 have a SQL injection vulnerability the id parameter of the /jeecg-boot/jmreport/show interface.9.8
Product normalization is registry-driven with AI assist and human review. How it works