J

Jeecg Security Vulnerabilities (CVE)

Explore vulnerabilities and security advisories affecting Jeecg products.

10 known CVE vulnerabilities tracked

Critical
0
High
0
Medium
2
Low
8
None
0

Vulnerabilities By Year

Products Affected

All Jeecg CVEs

CVE-2025-15126
3.1 low

A weakness has been identified in JeecgBoot up to 3.9.0. Affected by this vulnerability is the function getPositionUserList of the file /sys/position/getPositionUserList. This manipulation of the argument positionId causes improper authorization. The attack may be initiated remotely. The complexity

Jeecg Boot Dec 28, 2025
CVE-2025-15125
3.1 low

A security flaw has been discovered in JeecgBoot up to 3.9.0. Affected is the function queryDepartPermission of the file /sys/permission/queryDepartPermission. The manipulation of the argument departId results in improper authorization. The attack can be launched remotely. This attack is characteriz

Jeecg Boot Dec 28, 2025
CVE-2025-15124
3.1 low

A vulnerability was identified in JeecgBoot up to 3.9.0. This impacts the function getParameterMap of the file /sys/sysDepartPermission/list. The manipulation of the argument departId leads to improper authorization. The attack can be initiated remotely. The attack's complexity is rated as high. The

Jeecg Boot Dec 28, 2025
CVE-2025-15123
3.1 low

A vulnerability was determined in JeecgBoot up to 3.9.0. This affects an unknown function of the file /sys/sysDepartPermission/datarule/. Executing manipulation can lead to improper authorization. It is possible to launch the attack remotely. The attack requires a high level of complexity. The explo

Jeecg Boot Dec 28, 2025
CVE-2025-15122
3.1 low

A vulnerability was found in JeecgBoot up to 3.9.0. The impacted element is the function loadDatarule of the file /sys/sysDepartRole/datarule/. Performing manipulation of the argument departId/roleId results in improper authorization. It is possible to initiate the attack remotely. The attack is con

Jeecg Boot Dec 28, 2025
CVE-2025-15121
2.4 low

A vulnerability has been found in JeecgBoot up to 3.9.0. The affected element is the function getDeptRoleByUserId of the file /sys/sysDepartRole/getDeptRoleByUserId. Such manipulation of the argument departId leads to information disclosure. The vendor was contacted early about this disclosure but d

Jeecg Boot Dec 28, 2025
CVE-2025-15120
3.1 low

A flaw has been found in JeecgBoot up to 3.9.0. Impacted is the function getDeptRoleList of the file /sys/sysDepartRole/getDeptRoleList. This manipulation of the argument departId causes improper authorization. The attack is possible to be carried out remotely. A high degree of complexity is needed

Jeecg Boot Dec 28, 2025
CVE-2025-15119
3.1 low

A vulnerability was detected in JeecgBoot up to 3.9.0. This issue affects the function queryPageList of the file /sys/sysDepartRole/list. The manipulation of the argument deptId results in improper authorization. The attack can be executed remotely. A high complexity level is associated with this at

Jeecg Boot Dec 28, 2025
CVE-2025-14909
4.3 medium

A weakness has been identified in JeecgBoot up to 3.9.0. The impacted element is the function SysUserOnlineController of the file jeecg-boot/jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/system/controller/SysUserOnlineController.java. Executing manipulation can lead to manage

Jeecg Boot Dec 19, 2025
CVE-2025-14908
6.3 medium

A security flaw has been discovered in JeecgBoot up to 3.9.0. The affected element is an unknown function of the file jeecg-boot/jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/system/controller/SysTenantController.java of the component Multi-Tenant Management Module. Performing

Jeecg Boot Dec 19, 2025