İçeriğe atla
Noroxi

Jeesite kayıtları

jeesite üreticisine ait 19 yayımlanmış kayıt.

Tüm kayıtlar

19 kayıt
  • CVE-2020-19229
    39İzleyin

    Jeesite 1.2.7 uses the apache shiro version 1.2.3 affected by CVE-2016-4437.

    KritikCVSS 9,8İstismar yokEPSS %1

    jeesite · jeesite5 Nis 2022

  • CVE-2023-34601
    39İzleyin

    Jeesite before commit 10742d3 was discovered to contain a SQL injection vulnerability via the component ${businessTable} at /act/ActDao.xml.

    KritikCVSS 9,8İstismar yokEPSS %1

    jeesite · jeesite22 Haz 2023

  • CVE-2024-8112
    27İzleyin

    thinkgem JeeSite Cookie login cross site scripting

    OrtaCVSS 6,9İstismar yokEPSS %0

    jeesite · jeesite23 Ağu 2024

  • Jeesite 1.2.7 is affected by: XML External Entity (XXE).

    OrtaCVSS 6,5İstismar yokEPSS %1

    jeesite · jeesite23 Tem 2019

  • Jeesite 1.2.7 is affected by: SQL Injection.

    OrtaCVSS 6,5İstismar yokEPSS %1

    jeesite · jeesite23 Tem 2019

  • CVE-2025-5186
    21İzleyin

    thinkgem JeeSite URI Scheme form ResourceLoader.getResource server-side request forgery

    OrtaCVSS 5,3İstismar yokEPSS %0

    jeesite · jeesite26 May 2025

  • CVE-2023-38991
    21İzleyin

    An issue in the delete function in the ActModelController class of jeesite v1.2.6 allows authenticated attackers to arbitrarily delete model

    OrtaCVSS 5,4İstismar yokEPSS %0

    jeesite · jeesite3 Ağu 2023

  • CVE-2025-7863
    20İzleyin

    thinkgem JeeSite ServletUtils.java redirectUrl

    OrtaCVSS 5,1İstismar yokEPSS %0

    jeesite · jeesite19 Tem 2025

  • CVE-2023-38990
    17İzleyin

    An issue in the delete function in the MenuController class of jeesite v1.2.6 allows authenticated attackers to arbitrarily delete menus cre

    OrtaCVSS 4,3İstismar yokEPSS %1

    jeesite · jeesite1 Ağu 2023

  • CVE-2023-38988
    17İzleyin

    An issue in the delete function in the OaNotifyController class of jeesite v1.2.6 allows authenticated attackers to arbitrarily delete notif

    OrtaCVSS 4,3İstismar yokEPSS %0

    jeesite · jeesite28 Tem 2023

  • CVE-2023-38989
    17İzleyin

    An issue in the delete function in the UserController class of jeesite v1.2.6 allows authenticated attackers to arbitrarily delete the Admin

    OrtaCVSS 4,3İstismar yokEPSS %0

    jeesite · jeesite31 Tem 2023

  • CVE-2025-7763
    8İzleyin

    thinkgem JeeSite Site Controller SiteController.java select redirect

    DüşükCVSS 2,1İstismar yokEPSS %0

    jeesite · jeesite17 Tem 2025

  • CVE-2025-7785
    8İzleyin

    thinkgem JeeSite SsoController.java sso redirect

    DüşükCVSS 2,1İstismar yokEPSS %0

    jeesite · jeesite18 Tem 2025

  • CVE-2025-9796
    8İzleyin

    thinkgem JeeSite EncodeUtils.java decodeUrl2 cross site scripting

    DüşükCVSS 2,0İstismar yokEPSS %0

    jeesite · jeesite1 Eyl 2025

  • CVE-2025-7759
    8İzleyin

    thinkgem JeeSite UEditor Image Grabber ActionEnter.java server-side request forgery

    DüşükCVSS 2,1İstismar yokEPSS %0

    jeesite · jeesite17 Tem 2025

  • CVE-2025-7865
    8İzleyin

    thinkgem JeeSite XSS Filter EncodeUtils.java xssFilter cross site scripting

    DüşükCVSS 2,0İstismar yokEPSS %0

    jeesite · jeesite20 Tem 2025

  • CVE-2025-7864
    8İzleyin

    thinkgem JeeSite FileUploadController.java upload unrestricted upload

    DüşükCVSS 2,1İstismar yokEPSS %0

    jeesite · jeesite19 Tem 2025

  • CVE-2026-3405
    5İzleyin

    thinkgem JeeSite Connection path traversal

    DüşükCVSS 1,3İstismar yokEPSS %1

    jeesite · jeesite1 Mar 2026

  • CVE-2026-3404
    5İzleyin

    thinkgem JeeSite Endpoint CasOutHandler.java xml external entity reference

    DüşükCVSS 1,3İstismar yokEPSS %1

    jeesite · jeesite1 Mar 2026