Huayi-tec
Huayi-tec Jeewms: vulnerabilidades y CVE
Huayi-tec Jeewms tiene 19 vulnerabilidades publicadas, 4 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE19
Últimos 12 meses4
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-3028 | Baja (2.1) | 0.50% | — | 23 feb 2026 | A vulnerability was determined in erzhongxmu JEEWMS up to 3.7. This vulnerability affects the function doAdd of the file src/main/java/com/jeecg/demo/controller/JeecgListDemoController.java. This manipulation of the… |
| CVE-2025-70311 | Media (6.5) | 0.24% | — | 3 feb 2026 | JEEWMS 1.0 is vulnerable to SQL Injection. Attackers can inject malicious SQL statements through the id1 and id2 parameters in the /systemControl.do interface for attack. |
| CVE-2025-60268 | Media (6.5) | 0.36% | — | 10 oct 2025 | An arbitrary file upload vulnerability exists in JeeWMS 20250820, which is caused by the lack of file checking in the saveFiles function in /jeewms/cgUploadController.do. An attacker with normal privileges was able to… |
| CVE-2025-60269 | Crítica (9.4) | 0.33% | — | 10 oct 2025 | JEEWMS 20250820 is vulnerable to SQL Injection in the exportXls function located in the src/main/java/org/jeecgframework/web/cgreport/controller/excel/CgExportExcelController.java file. |
| CVE-2025-55834 | Media (6.1) | 0.33% | — | 16 sept 2025 | A Cross Site Scripting vulnerability in JeeWMS v.3.7 and before allows a remote attacker to obtain sensitive information via the logController.do component |
| CVE-2025-5390 | Media (5.3) | 0.32% | — | 31 may 2025 | A vulnerability, which was classified as critical, was found in JeeWMS up to 20250504. This affects the function filedeal of the file /systemController/filedeal.do of the component File Handler. The manipulation leads… |
| CVE-2025-5389 | Media (5.3) | 0.34% | — | 31 may 2025 | A vulnerability, which was classified as critical, has been found in JeeWMS up to 20250504. Affected by this issue is the function dogenerateOne2Many of the file /generateController.do?dogenerateOne2Many of the… |
| CVE-2025-5388 | Media (5.3) | 0.36% | — | 31 may 2025 | A vulnerability classified as critical was found in JeeWMS up to 20250504. Affected by this vulnerability is the function dogenerate of the file /generateController.do?dogenerate. The manipulation leads to sql… |
| CVE-2025-5387 | Media (5.3) | 0.34% | — | 31 may 2025 | A vulnerability classified as critical has been found in JeeWMS up to 20250504. Affected is the function dogenerate of the file /generateController.do?dogenerate of the component File Handler. The manipulation leads to… |
| CVE-2025-5386 | Media (5.3) | 0.33% | — | 31 may 2025 | A vulnerability was found in JeeWMS up to 20250504. It has been rated as critical. This issue affects the function transEditor of the file /cgformTransController.do?transEditor. The manipulation leads to sql injection.… |
| CVE-2025-5385 | Media (5.3) | 0.48% | — | 31 may 2025 | A vulnerability was found in JeeWMS up to 20250504. It has been declared as critical. This vulnerability affects the function doAdd of the file /cgformTemplateController.do?doAdd. The manipulation leads to path… |
| CVE-2025-5384 | Media (5.3) | 0.33% | — | 31 may 2025 | A vulnerability was found in JeeWMS up to 20250504. It has been classified as critical. This affects the function CgAutoListController of the file /cgAutoListController.do?datagrid. The manipulation leads to sql… |
| CVE-2024-57761 | Alta (8.1) | 0.48% | — | 15 ene 2025 | An arbitrary file upload vulnerability in the parserXML() method of JeeWMS before v2025.01.01 allows attackers to execute arbitrary code via uploading a crafted file. |
| CVE-2025-0392 | Media (5.3) | 0.65% | — | 11 ene 2025 | A vulnerability, which was classified as critical, was found in Guangzhou Huayi Intelligent Technology Jeewms up to 20241229. Affected is the function datagridGraph of the file /graphReportController.do. The… |
| CVE-2025-0391 | Media (5.3) | 0.52% | — | 11 ene 2025 | A vulnerability, which was classified as critical, has been found in Guangzhou Huayi Intelligent Technology Jeewms up to 20241229. This issue affects the function saveOrUpdate of the file… |
| CVE-2025-0390 | Media (6.9) | 0.83% | — | 11 ene 2025 | A vulnerability classified as critical was found in Guangzhou Huayi Intelligent Technology Jeewms up to 20241229. This vulnerability affects unknown code of the file /wmOmNoticeHController.do. The manipulation leads to… |
| CVE-2024-12347 | Media (6.9) | 0.62% | — | 9 dic 2024 | A vulnerability was found in Guangzhou Huayi Intelligent Technology Jeewms up to 1.0.0 and classified as critical. This issue affects some unknown processing of the file /jeewms_war/webpage/system/druid/index.html of… |
| CVE-2024-11961 | Media (6.9) | 0.87% | — | 28 nov 2024 | A vulnerability was found in Guangzhou Huayi Intelligent Technology Jeewms 3.7. It has been rated as problematic. This issue affects the function preHandle of the file… |
| CVE-2024-11251 | Media (5.3) | 0.53% | — | 15 nov 2024 | A vulnerability was found in erzhongxmu Jeewms up to 20241108. It has been rated as critical. This issue affects some unknown processing of the file cgReportController.do of the component AuthInterceptor. The… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.