Vulnerabilidades em jeecgboot
10 resultadosAnálise Vexday
JeecgBoot possui 10 vulnerabilidades catalogadas, com 3 publicadas nos últimos 90 dias, indicando descobertas recentes. Nenhuma está sob exploração ativa em campo (KEV) e não há críticas de severidade máxima, reduzindo o risco imediato. A fraqueza dominante é validação inadequada de entrada (CWE-20), padrão comum que merece atenção em processos de hardening.
CVE-2023-4450MEDIUMjeecgboot JimuReport Template injectionEPSS 11.4%CVE-2023-6307MEDIUMjeecgboot JimuReport image path traversalEPSS 0.8%CVE-2025-10771MEDIUMjeecgboot JimuReport DB2 JDBC testConnection deserializationEPSS 0.6%CVE-2025-8963MEDIUMjeecgboot JimuReport Data Large Screen Template testConnection deserializationEPSS 0.5%CVE-2026-58375HIGHJimuReport 2.5.0 - Unauthenticated Report Export via /jmreport/auto/exportEPSS 0.5%CVE-2025-10770MEDIUMjeecgboot JimuReport MySQL JDBC testConnection deserializationEPSS 0.4%CVE-2025-12626MEDIUMjeecgboot jeewx-boot WxActGoldeneggsPrizesController.java getImgUrl path traversalEPSS 0.3%CVE-2026-5848MEDIUMjeecgboot JimuReport Data Source testConnection DriverManager.getConnection code injectionEPSS 0.3%CVE-2026-10241MEDIUMjeecgboot The server processes these URLs Cloud Instance Metadata Endpoint debug FileDownloadUtils.download2DiskFromNet server-side request forgeryEPSS 0.3%CVE-2026-58377HIGHJeecgBoot 3.9.2 - Missing Authorization on OpenAPI Credential Management Endpoints Exposes Access/Secret KeysEPSS 0.3%