Jeecg
Jeecg Jimureport: vulnerabilidades y CVE
Jeecg Jimureport tiene 12 vulnerabilidades publicadas, 6 de ellas en los últimos 12 meses. 5 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE12
Últimos 12 meses6
Críticas5
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-75479 | Alta (8.7) | 0.46% | — | 17 ago 2026 | JimuReport contains an authentication bypass vulnerability in the report folder template listing endpoint that allows unauthenticated attackers to enumerate all reports and retrieve share tokens. Attackers can use… |
| CVE-2026-58375 | Alta (8.7) | 0.63% | — | 30 jun 2026 | JimuReport through 2.5.0 exposes the POST /jmreport/auto/export endpoint without authentication: the handler is annotated @JimuNoLoginRequired, so JimuReportTokenInterceptor skips all authentication and authorization,… |
| CVE-2026-36418 | Crítica (9.1) | 0.66% | — | 17 jun 2026 | JimuReport versions 2.3.4 and below are vulnerable to remote code execution due to improper handling of Aviator expressions. The /jmreport/executeSelectApi endpoint passes user-supplied input directly to the Aviator… |
| CVE-2026-11457 | Media (5.5) | 0.33% | — | 7 jun 2026 | A security flaw has been discovered in erzhongxmu JeeWMS up to 141740afb2ba14d441c82a833d0a418d07ca2d69. This vulnerability affects unknown code of the file /base-boot/jmreport/testConnection of the component JimuReport… |
| CVE-2026-5848 | Baja (2) | 0.43% | — | 9 abr 2026 | A vulnerability was found in jeecgboot JimuReport up to 2.3.0. The affected element is the function DriverManager.getConnection of the file /drag/onlDragDataSource/testConnection of the component Data Source Handler.… |
| CVE-2025-66913 | Crítica (9.8) | 1.1% | — | 8 ene 2026 | JimuReport thru version 2.1.3 is vulnerable to remote code execution when processing user-controlled H2 JDBC URLs. The application passes the attacker-supplied JDBC URL directly to the H2 driver, allowing the use of… |
| CVE-2025-10771 | Baja (2.1) | 0.61% | — | 21 sept 2025 | A vulnerability was determined in jeecgboot JimuReport up to 2.1.2. Affected is an unknown function of the file /drag/onlDragDataSource/testConnection of the component DB2 JDBC Handler. Executing manipulation of the… |
| CVE-2025-10770 | Baja (2.1) | 0.43% | — | 21 sept 2025 | A vulnerability was found in jeecgboot JimuReport up to 2.1.2. This impacts an unknown function of the file /drag/onlDragDataSource/testConnection of the component MySQL JDBC Handler. Performing manipulation results in… |
| CVE-2025-8963 | Media (5.3) | 0.49% | — | 14 ago 2025 | A vulnerability was determined in jeecgboot JimuReport up to 2.1.1. Affected by this issue is some unknown functionality of the file /drag/onlDragDataSource/testConnection of the component Data Large Screen Template.… |
| CVE-2024-44893 | Crítica (9.8) | 0.53% | — | 10 sept 2024 | An issue in the component /jeecg-boot/jmreport/dict/list of JimuReport v1.7.8 allows attacker to escalate privileges via a crafted GET request. |
| CVE-2023-6307 | Crítica (9.8) | 0.84% | — | 27 nov 2023 | A vulnerability classified as critical was found in jeecgboot JimuReport up to 1.6.1. Affected by this vulnerability is an unknown functionality of the file /download/image. The manipulation of the argument imageUrl… |
| CVE-2023-4450 | Crítica (9.8) | 12% | — | 21 ago 2023 | A vulnerability was found in jeecgboot JimuReport up to 1.6.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Template Handler. The manipulation leads to… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.