jeecg CVE Vulnerabilities & Metrics

Focus on jeecg vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About jeecg Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with jeecg. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total jeecg CVEs: 35
Earliest CVE date: 06 Aug 2021, 23:15 UTC
Latest CVE date: 03 Jan 2024, 21:15 UTC

Latest CVE reference: CVE-2023-49442

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 0

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): -100.0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): -100.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical jeecg CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 2.15

Max CVSS: 10.0

Critical CVEs (≥9): 1

CVSS Range vs. Count

Range Count
0.0-3.9 23
4.0-6.9 8
7.0-8.9 3
9.0-10.0 1

CVSS Distribution Chart

Top 5 Highest CVSS jeecg CVEs

These are the five CVEs with the highest CVSS scores for jeecg, sorted by severity first and recency.

All CVEs for jeecg

CVE-2023-49442 jeecg vulnerability CVSS: 0 03 Jan 2024, 21:15 UTC

Deserialization of Untrusted Data in jeecgFormDemoController in JEECG 4.0 and earlier allows attackers to run arbitrary code via crafted POST request.

CVE-2023-41544 jeecg vulnerability CVSS: 0 30 Dec 2023, 04:15 UTC

SSTI injection vulnerability in jeecg-boot version 3.5.3, allows remote attackers to execute arbitrary code via crafted HTTP request to the /jmreport/loadTableData component.

CVE-2023-41543 jeecg vulnerability CVSS: 0 30 Dec 2023, 02:15 UTC

SQL injection vulnerability in jeecg-boot v3.5.3, allows remote attackers to escalate privileges and obtain sensitive information via the component /sys/replicate/check.

CVE-2023-41542 jeecg vulnerability CVSS: 0 30 Dec 2023, 02:15 UTC

SQL injection vulnerability in jeecg-boot version 3.5.3, allows remote attackers to escalate privileges and obtain sensitive information via the jmreport/qurestSql component.

CVE-2023-6307 jeecg vulnerability CVSS: 6.5 27 Nov 2023, 02:15 UTC

A vulnerability classified as critical was found in jeecgboot JimuReport up to 1.6.1. Affected by this vulnerability is an unknown functionality of the file /download/image. The manipulation of the argument imageUrl leads to relative path traversal. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-246133 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2023-47467 jeecg vulnerability CVSS: 0 22 Nov 2023, 18:15 UTC

Directory Traversal vulnerability in jeecg-boot v.3.6.0 allows a remote privileged attacker to obtain sensitive information via the file directory structure.

CVE-2023-40989 jeecg vulnerability CVSS: 0 22 Sep 2023, 20:15 UTC

SQL injection vulnerbility in jeecgboot jeecg-boot v 3.0, 3.5.3 that allows a remote attacker to execute arbitrary code via a crafted request to the report/jeecgboot/jmreport/queryFieldBySql component.

CVE-2023-42268 jeecg vulnerability CVSS: 0 08 Sep 2023, 19:15 UTC

Jeecg boot up to v3.5.3 was discovered to contain a SQL injection vulnerability via the component /jeecg-boot/jmreport/show.

CVE-2023-41578 jeecg vulnerability CVSS: 0 08 Sep 2023, 19:15 UTC

Jeecg boot up to v3.5.3 was discovered to contain an arbitrary file read vulnerability via the interface /testConnection.

CVE-2023-4450 jeecg vulnerability CVSS: 6.5 21 Aug 2023, 03:15 UTC

A vulnerability was found in jeecgboot JimuReport up to 1.6.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Template Handler. The manipulation leads to injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.6.1 is able to address this issue. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-237571.

CVE-2023-38905 jeecg vulnerability CVSS: 0 17 Aug 2023, 19:15 UTC

SQL injection vulnerability in Jeecg-boot v.3.5.0 and before allows a local attacker to cause a denial of service via the Benchmark, PG_Sleep, DBMS_Lock.Sleep, Waitfor, DECODE, and DBMS_PIPE.RECEIVE_MESSAGE functions.

CVE-2023-38992 jeecg vulnerability CVSS: 0 28 Jul 2023, 15:15 UTC

jeecg-boot v3.5.1 was discovered to contain a SQL injection vulnerability via the title parameter at /sys/dict/loadTreeData.

CVE-2023-34660 jeecg vulnerability CVSS: 0 16 Jun 2023, 18:15 UTC

jjeecg-boot V3.5.0 has an unauthorized arbitrary file upload in /jeecg-boot/jmreport/upload interface.

CVE-2023-34659 jeecg vulnerability CVSS: 0 16 Jun 2023, 18:15 UTC

jeecg-boot 3.5.0 and 3.5.1 have a SQL injection vulnerability the id parameter of the /jeecg-boot/jmreport/show interface.

CVE-2023-1784 jeecg vulnerability CVSS: 5.0 31 Mar 2023, 20:15 UTC

A vulnerability was found in jeecg-boot 3.5.0 and classified as critical. This issue affects some unknown processing of the component API Documentation. The manipulation leads to improper authentication. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-224699.

CVE-2023-1741 jeecg vulnerability CVSS: 4.0 30 Mar 2023, 22:15 UTC

A vulnerability was found in jeecg-boot 3.5.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file SysDictMapper.java of the component Sleep Command Handler. The manipulation leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-224629 was assigned to this vulnerability.

CVE-2023-1454 jeecg vulnerability CVSS: 6.5 17 Mar 2023, 07:15 UTC

A vulnerability classified as critical has been found in jeecg-boot 3.5.0. This affects an unknown part of the file jmreport/qurestSql. The manipulation of the argument apiSelectId leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-223299.

CVE-2023-24789 jeecg vulnerability CVSS: 0 06 Mar 2023, 16:15 UTC

jeecg-boot v3.4.4 was discovered to contain an authenticated SQL injection vulnerability via the building block report component.

CVE-2021-37306 jeecg vulnerability CVSS: 0 03 Feb 2023, 18:15 UTC

An Insecure Permissions issue in jeecg-boot 2.4.5 and earlier allows remote attackers to gain escalated privilege and view sensitive information via api uri: api uri:/sys/user/checkOnlyUser?username=admin.

CVE-2021-37305 jeecg vulnerability CVSS: 0 03 Feb 2023, 18:15 UTC

An Insecure Permissions issue in jeecg-boot 2.4.5 and earlier allows remote attackers to gain escalated privilege and view sensitive information via api uri: /sys/user/querySysUser?username=admin.

CVE-2021-37304 jeecg vulnerability CVSS: 0 03 Feb 2023, 18:15 UTC

An Insecure Permissions issue in jeecg-boot 2.4.5 allows unauthenticated remote attackers to gain escalated privilege and view sensitive information via the httptrace interface.

CVE-2022-47105 jeecg vulnerability CVSS: 0 19 Jan 2023, 16:15 UTC

Jeecg-boot v3.4.4 was discovered to contain a SQL injection vulnerability via the component /sys/dict/queryTableData.

CVE-2022-45210 jeecg vulnerability CVSS: 0 25 Nov 2022, 17:15 UTC

Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/user/deleteRecycleBin.

CVE-2022-45208 jeecg vulnerability CVSS: 0 25 Nov 2022, 17:15 UTC

Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/user/putRecycleBin.

CVE-2022-45207 jeecg vulnerability CVSS: 0 25 Nov 2022, 17:15 UTC

Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component updateNullByEmptyString.

CVE-2022-45206 jeecg vulnerability CVSS: 0 25 Nov 2022, 17:15 UTC

Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/duplicate/check.

CVE-2022-45205 jeecg vulnerability CVSS: 0 25 Nov 2022, 17:15 UTC

Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/dict/queryTableData.

CVE-2022-2647 jeecg vulnerability CVSS: 0 04 Aug 2022, 09:15 UTC

A vulnerability was found in jeecg-boot. It has been declared as critical. This vulnerability affects unknown code of the file /api/. The manipulation of the argument file leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-205594 is the identifier assigned to this vulnerability.

CVE-2021-44585 jeecg vulnerability CVSS: 4.3 10 Mar 2022, 21:15 UTC

A Cross Site Scripting (XSS) vulnerabilitiy exits in jeecg-boot 3.0 in /jeecg-boot/jmreport/view with a mouseover event.

CVE-2022-22881 jeecg vulnerability CVSS: 7.5 16 Feb 2022, 22:15 UTC

Jeecg-boot v3.0 was discovered to contain a SQL injection vulnerability via the code parameter in /sys/user/queryUserComponentData.

CVE-2022-22880 jeecg vulnerability CVSS: 7.5 16 Feb 2022, 22:15 UTC

Jeecg-boot v3.0 was discovered to contain a SQL injection vulnerability via the code parameter in /jeecg-boot/sys/user/queryUserByDepId.

CVE-2021-46089 jeecg vulnerability CVSS: 10.0 25 Jan 2022, 15:15 UTC

In JeecgBoot 3.0, there is a SQL injection vulnerability that can operate the database with root privileges.

CVE-2020-20948 jeecg vulnerability CVSS: 5.0 27 Dec 2021, 21:15 UTC

An arbitrary file download vulnerability in jeecg v3.8 allows attackers to access sensitive files via modification of the "localPath" variable.

CVE-2020-28088 jeecg vulnerability CVSS: 7.5 06 Aug 2021, 23:15 UTC

An arbitrary file upload vulnerability in /jeecg-boot/sys/common/upload of jeecg-boot CMS 2.3 allows attackers to execute arbitrary code.

CVE-2020-28087 jeecg vulnerability CVSS: 5.0 06 Aug 2021, 23:15 UTC

A SQL injection vulnerability in /jeecg boot/sys/dict/loadtreedata of jeecg-boot CMS 2.3 allows attackers to access sensitive database information.