Vulnerabilities > Jeecg > Jeecg Boot

DATE CVE VULNERABILITY TITLE RISK
2023-06-16 CVE-2023-34660 Unrestricted Upload of File with Dangerous Type vulnerability in Jeecg Boot 3.5.0/3.5.1
jjeecg-boot V3.5.0 has an unauthorized arbitrary file upload in /jeecg-boot/jmreport/upload interface.
network
low complexity
jeecg CWE-434
6.5
2023-03-31 CVE-2023-1784 Improper Authentication vulnerability in Jeecg Boot 3.5.0
A vulnerability was found in jeecg-boot 3.5.0 and classified as critical.
network
low complexity
jeecg CWE-287
critical
9.8
2023-03-30 CVE-2023-1741 SQL Injection vulnerability in Jeecg Boot 3.5.0
A vulnerability was found in jeecg-boot 3.5.0.
network
low complexity
jeecg CWE-89
critical
9.8
2023-03-17 CVE-2023-1454 SQL Injection vulnerability in Jeecg Jeecg-Boot 3.5.0
A vulnerability classified as critical has been found in jeecg-boot 3.5.0.
network
low complexity
jeecg CWE-89
critical
9.8
2023-01-19 CVE-2022-47105 SQL Injection vulnerability in Jeecg Boot 3.4.4
Jeecg-boot v3.4.4 was discovered to contain a SQL injection vulnerability via the component /sys/dict/queryTableData.
network
low complexity
jeecg CWE-89
critical
9.8
2022-11-25 CVE-2022-45205 SQL Injection vulnerability in Jeecg Boot 3.4.3
Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/dict/queryTableData.
network
low complexity
jeecg CWE-89
5.3
2022-11-25 CVE-2022-45206 SQL Injection vulnerability in Jeecg Boot 3.4.3
Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/duplicate/check.
network
low complexity
jeecg CWE-89
critical
9.8
2022-11-25 CVE-2022-45207 SQL Injection vulnerability in Jeecg Boot 3.4.3
Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component updateNullByEmptyString.
network
low complexity
jeecg CWE-89
critical
9.8
2022-11-25 CVE-2022-45208 SQL Injection vulnerability in Jeecg Boot 3.4.3
Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/user/putRecycleBin.
network
low complexity
jeecg CWE-89
4.3
2022-11-25 CVE-2022-45210 SQL Injection vulnerability in Jeecg Boot 3.4.3
Jeecg-boot v3.4.3 was discovered to contain a SQL injection vulnerability via the component /sys/user/deleteRecycleBin.
network
low complexity
jeecg CWE-89
4.3