CVE Tools

Jeecg

30 CVEs tracked since 2022. Since Nov 2022, none of them reached CISA KEV.

Jeecg CVEs per month

Nov 2022 to Dec 2025. Point at a month, or focus the strip and use the arrow keys.
Jeecg CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2022-1150
2022-12null or fewer
2023-01null or fewer
2023-02null or fewer
2023-03null or fewer
2023-04null or fewer
2023-05null or fewer
2023-0640
2023-07null or fewer
2023-08null or fewer
2023-09null or fewer
2023-10null or fewer
2023-11null or fewer
2023-12null or fewer
2024-01null or fewer
2024-02null or fewer
2024-03null or fewer
2024-04null or fewer
2024-05null or fewer
2024-06null or fewer
2024-07null or fewer
2024-08null or fewer
2024-09null or fewer
2024-10null or fewer
2024-11null or fewer
2024-12null or fewer
2025-01null or fewer
2025-02null or fewer
2025-03null or fewer
2025-04null or fewer
2025-05null or fewer
2025-06null or fewer
2025-07null or fewer
2025-08null or fewer
2025-09110
2025-10null or fewer
2025-11null or fewer
2025-12100

Products

The products that kept showing up in Jeecg's monthly top three, with their CVEs summed over those months.

  1. Jeecg Boot264 months
  2. Jeecgboot21 month
  3. Jimureport21 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Jeecg.

  1. CVE-2024-43028A command injection vulnerability in the component /jmreport/show of jeecg boot v3.0.0 to v3.5.3 allows attackers to execute arbitrary code via a crafted HTTP request.9.8
  2. CVE-2024-40489There is an injection vulnerability in jeecg boot versions 3.0.0 to 3.5.3 due to lax character filtering, which allows attackers to execute arbitrary code on components through specially crafted HT...9.8
  3. CVE-2026-2945JeecgBoot uploadImgByHttp server-side request forgery6.3
  4. CVE-2026-2822JeecgBoot Backend airag_app,1,create_by sql injection6.3
  5. CVE-2026-2555JeecgBoot Retrieval-Augmented Generation AiragKnowledgeController.java importDocumentFromZip deserialization5.0
  6. CVE-2026-2111JeecgBoot Retrieval-Augmented Generation edit path traversal4.3
  7. CVE-2026-1746JeecgBoot Online Report API loadDictItemByKeyword sql injection6.3
  8. CVE-2025-66913JimuReport thru version 2.1.3 is vulnerable to remote code execution when processing user-controlled H2 JDBC URLs. The application passes the attacker-supplied JDBC URL directly to the H2 driver, a...9.8
  9. CVE-2025-15126JeecgBoot getPositionUserList improper authorization3.1
  10. CVE-2025-15125JeecgBoot queryDepartPermission improper authorization3.1
  11. CVE-2025-15124JeecgBoot list getParameterMap improper authorization3.1
  12. CVE-2025-15123JeecgBoot datarule improper authorization3.1
  13. CVE-2025-15122JeecgBoot datarule loadDatarule improper authorization3.1
  14. CVE-2025-15121JeecgBoot getDeptRoleByUserId information disclosure2.4
  15. CVE-2025-15120JeecgBoot getDeptRoleList improper authorization3.1

The record

Peak rank
#65 in Sep 2025
Busiest month shown
Sep 2025, 11 CVEs
Months with a KEV entry
0 since Nov 2022
Monthly snapshots
4 since 2022
Jeecg's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store