Jishenghua
Jishenghua Jsherp: vulnerabilidades y CVE
Jishenghua Jsherp tiene 30 vulnerabilidades publicadas, 16 de ellas en los últimos 12 meses. 9 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE30
Últimos 12 meses16
Críticas9
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-105621 | Baja (2.1) | — | — | 6 oct 2026 | A security flaw has been discovered in jishenghua jshERP up to 3.5. Affected is the function updateAccountHeadAndDetail of the file jshERP-boot/src/main/java/com/jsh/erp/service/AccountHeadService.java of the component… |
| CVE-2026-11469 | Baja (2) | 0.23% | — | 8 jun 2026 | A flaw has been found in jishenghua jshERP up to 3.6. Impacted is the function insertPlatformConfig of the file jshERP-boot/src/main/java/com/jsh/erp/service/PlatformConfigService.java of the component platformConfig… |
| CVE-2026-11467 | Baja (2.1) | 0.32% | — | 8 jun 2026 | A security vulnerability has been detected in jishenghua jshERP up to 3.6. This vulnerability affects the function addAccountHeadAndDetail of the file… |
| CVE-2026-8320 | Baja (2) | 0.38% | — | 11 may 2026 | A security vulnerability has been detected in jishenghua jshERP up to 3.6. This affects the function getUserByWeixinCode of the file jshERP-boot/src/main/java/com/jsh/erp/service/UserService.java of the component… |
| CVE-2026-1588 | Baja (2) | 0.67% | — | 29 ene 2026 | A vulnerability was found in jishenghua jshERP up to 3.6. The impacted element is the function install of the file /jshERP-boot/plugin/installByPath of the component… |
| CVE-2026-1549 | Baja (2.1) | 0.52% | — | 28 ene 2026 | A vulnerability was identified in jishenghua jshERP up to 3.6. Affected by this vulnerability is an unknown functionality of the file /jshERP-boot/plugin/uploadPluginConfigFile of the component PluginController. Such… |
| CVE-2026-1546 | Baja (2.1) | 0.38% | — | 28 ene 2026 | A security vulnerability has been detected in jishenghua jshERP up to 3.6. The impacted element is the function getBillItemByParam of the file /jshERP-boot/depotItem/importItemExcel of the component… |
| CVE-2025-67344 | Media (4.6) | 0.17% | — | 12 dic 2025 | jshERP v3.5 and earlier is affected by a stored Cross Site Scripting (XSS) vulnerability via the /msg/add endpoint. |
| CVE-2025-67341 | Media (4.6) | 0.17% | — | 12 dic 2025 | jshERP versions 3.5 and earlier are affected by a stored XSS vulnerability. This vulnerability allows attackers to upload PDF files containing XSS payloads. Additionally, these PDF files can be accessed via static URLs,… |
| CVE-2025-51746 | Crítica (9.8) | 0.48% | — | 25 nov 2025 | An issue was discovered in jishenghua JSH_ERP 2.3.1. The /serialNumber/addSerialNumber endpoint is vulnerable to fastjson deserialization attacks. |
| CVE-2025-51745 | Crítica (9.8) | 0.48% | — | 25 nov 2025 | An issue was discovered in jishenghua JSH_ERP 2.3.1. The /role/addcan endpoint is vulnerable to fastjson deserialization attacks. |
| CVE-2025-51744 | Crítica (9.8) | 0.48% | — | 25 nov 2025 | An issue was discovered in jishenghua JSH_ERP 2.3.1. The /user/addUser endpoint is vulnerable to fastjson deserialization attacks. |
| CVE-2025-51743 | Crítica (9.8) | 0.48% | — | 25 nov 2025 | An issue was discovered in jishenghua JSH_ERP 2.3.1. The /materialCategory/addMaterialCategory endpoint is vulnerable to fastjson deserialization attacks. |
| CVE-2025-51742 | Crítica (9.8) | 0.48% | — | 25 nov 2025 | An issue was discovered in jishenghua JSH_ERP 2.3.1. The /material/getMaterialEnableSerialNumberList endpoint passes the search query parameter directly to parseObject(), introducing a Fastjson deserialization… |
| CVE-2025-60800 | Alta (7.5) | 0.32% | — | 28 oct 2025 | Incorrect access control in the /jshERP-boot/user/info interface of jshERP up to commit 90c411a allows attackers to access sensitive information via a crafted GET request. |
| CVE-2025-60801 | Alta (8.2) | 0.46% | — | 24 oct 2025 | jshERP up to commit fbda24da was discovered to contain an unauthenticated remote code execution (RCE) vulnerability via the jsh_erp function. |
| CVE-2025-55371 | Media (5.3) | 0.32% | — | 21 ago 2025 | Incorrect access control in the component /controller/PersonController.java of jshERP v3.5 allows unauthorized attackers to obtain all the information of the handler by executing the getAllList method. |
| CVE-2025-55370 | Alta (8.8) | 0.38% | — | 21 ago 2025 | Incorrect access control in the component \controller\ResourceController.java of jshERP v3.5 allows unauthorized attackers to obtain all the corresponding ID data by modifying the ID value. |
| CVE-2025-55368 | Alta (8.8) | 0.38% | — | 21 ago 2025 | Incorrect access control in the component \controller\RoleController.java of jshERP v3.5 allows unauthorized attackers to arbitrarily modify the supplier status under any account. |
| CVE-2025-55367 | Media (5.3) | 0.32% | — | 21 ago 2025 | Incorrect access control in the component \controller\SupplierController.java of jshERP v3.5 allows unauthorized attackers to arbitrarily modify the supplier status under any account. |
| CVE-2025-55366 | Media (5.3) | 0.32% | — | 21 ago 2025 | Incorrect access control in the component \controller\UserController.java of jshERP v3.5 allows attackers to arbitrarily reset user account passwords and execute a horizontal privilege escalation attack. |
| CVE-2025-8840 | Baja (2.1) | 0.44% | — | 11 ago 2025 | A vulnerability was determined in jshERP up to 3.5. Affected is an unknown function of the file /jshERP-boot/user/deleteBatch of the component Endpoint. The manipulation of the argument ids leads to improper… |
| CVE-2025-8839 | Baja (2.1) | 0.34% | — | 11 ago 2025 | A vulnerability was found in jshERP up to 3.5. This issue affects some unknown processing of the file /jshERP-boot/user/addUser of the component Endpoint. The manipulation leads to improper authorization. The attack may… |
| CVE-2025-7948 | Baja (2.1) | 0.38% | — | 22 jul 2025 | A vulnerability classified as problematic was found in jshERP up to 3.5. Affected by this vulnerability is an unknown functionality of the file /jshERP-boot/user/updatePwd. The manipulation leads to weak password… |
| CVE-2025-7947 | Baja (2.1) | 0.40% | — | 22 jul 2025 | A vulnerability classified as critical has been found in jshERP up to 3.5. Affected is an unknown function of the file /user/delete of the component Account Handler. The manipulation of the argument ID leads to improper… |
| CVE-2025-7566 | Baja (2) | 0.65% | — | 14 jul 2025 | A vulnerability has been found in jshERP up to 3.5 and classified as critical. This vulnerability affects the function exportExcelByParam of the file /src/main/java/com/jsh/erp/controller/SystemConfigController.java.… |
| CVE-2024-24003 | Crítica (9.8) | 0.80% | — | 8 feb 2024 | jshERP v3.3 is vulnerable to SQL Injection. The com.jsh.erp.controller.DepotHeadController: com.jsh.erp.utils.BaseResponseInfo findInOutMaterialCount() function of jshERP does not filter `column` and `order` parameters… |
| CVE-2024-24004 | Crítica (9.8) | 0.68% | — | 7 feb 2024 | jshERP v3.3 is vulnerable to SQL Injection. The com.jsh.erp.controller.DepotHeadController: com.jsh.erp.utils.BaseResponseInfo findInOutDetail() function of jshERP does not filter `column` and `order` parameters well… |
| CVE-2024-24002 | Crítica (9.8) | 0.77% | — | 7 feb 2024 | jshERP v3.3 is vulnerable to SQL Injection. The com.jsh.erp.controller.MaterialController: com.jsh.erp.utils.BaseResponseInfo getListWithStock() function of jshERP does not filter `column` and `order` parameters well… |
| CVE-2024-24001 | Crítica (9.8) | 0.68% | — | 7 feb 2024 | jshERP v3.3 is vulnerable to SQL Injection. via the com.jsh.erp.controller.DepotHeadController: com.jsh.erp.utils.BaseResponseInfo findallocationDetail() function of jshERP which allows an attacker to construct… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.