Jimureport
This hub aggregates every CVE we track for Jimureport, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
10
CVEs tracked
2
Critical
2
High
0
In CISA KEV
Severity distribution
MEDIUM6HIGH2CRITICAL2
Monthly trend
0
0
0
0
0
0
0
0
0
0
1
2
0
0
0
1
0
0
1
0
1
0
1
0
2024-102026-09
Latest CVEs
The 10 most recently published vulnerabilities affecting Jimureport.
- CVE-2026-75479JimuReport Unauthenticated Report Listing and Share Token Disclosure7.5
- CVE-2026-58375JimuReport 2.5.0 - Unauthenticated Report Export via /jmreport/auto/export7.5
- CVE-2026-5848jeecgboot JimuReport Data Source testConnection DriverManager.getConnection code injection4.7
- CVE-2025-66913JimuReport thru version 2.1.3 is vulnerable to remote code execution when processing user-controlled H2 JDBC URLs. The application passes the attacker-supplied JDBC URL directly to the H2 driver, a...9.8
- CVE-2025-10771jeecgboot JimuReport DB2 JDBC testConnection deserialization6.3
- CVE-2025-10770jeecgboot JimuReport MySQL JDBC testConnection deserialization6.3
- CVE-2025-8963jeecgboot JimuReport Data Large Screen Template testConnection deserialization6.3
- CVE-2024-44893An issue in the component /jeecg-boot/jmreport/dict/list of JimuReport v1.7.8 allows attacker to escalate privileges via a crafted GET request.9.8
- CVE-2023-6307jeecgboot JimuReport image path traversal6.3
- CVE-2023-4450jeecgboot JimuReport Template injection6.3
Product normalization is registry-driven with AI assist and human review. How it works