Jeesite records
19 published records for vendor jeesite.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 5.3%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')3
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-918 Server-Side Request Forgery (SSRF)2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-732 Incorrect Permission Assignment for Critical Resource1
The weakness classes this vendor ships most often: where to look.
CWEAll records
19 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2020-19229No exploit | Jeesite 1.2.7 uses the apache shiro version 1.2.3 affected by CVE-2016-4437.jeesite · jeesite · CWE-502 | Critical9.8 | — | 1.4% | Apr 5, 2022 |
39Monitor | CVE-2023-34601No exploit | Jeesite before commit 10742d3 was discovered to contain a SQL injection vulnerability via the component ${businessTable} at /act/ActDao.xml.jeesite · jeesite · CWE-89 | Critical9.8 | — | 0.7% | Jun 22, 2023 |
27Monitor | CVE-2024-8112No exploit | thinkgem JeeSite Cookie login cross site scriptingjeesite · jeesite · CWE-79 | Medium6.9 | — | 0.5% | Aug 23, 2024 |
26Monitor | CVE-2019-1010202No exploit | Jeesite 1.2.7 is affected by: XML External Entity (XXE).jeesite · jeesite · CWE-611 | Medium6.5 | — | 1.3% | Jul 23, 2019 |
26Monitor | CVE-2019-1010201No exploit | Jeesite 1.2.7 is affected by: SQL Injection.jeesite · jeesite · CWE-89 | Medium6.5 | — | 1.2% | Jul 23, 2019 |
21Monitor | CVE-2025-5186No exploit | thinkgem JeeSite URI Scheme form ResourceLoader.getResource server-side request forgeryjeesite · jeesite · CWE-918 | Medium5.3 | — | 0.5% | May 26, 2025 |
21Monitor | CVE-2023-38991No exploit | An issue in the delete function in the ActModelController class of jeesite v1.2.6 allows authenticated attackers to arbitrarily delete modeljeesite · jeesite · CWE-732 | Medium5.4 | — | 0.5% | Aug 3, 2023 |
20Monitor | CVE-2025-7863No exploit | thinkgem JeeSite ServletUtils.java redirectUrljeesite · jeesite · CWE-601 | Medium5.1 | — | 0.4% | Jul 19, 2025 |
17Monitor | CVE-2023-38990No exploit | An issue in the delete function in the MenuController class of jeesite v1.2.6 allows authenticated attackers to arbitrarily delete menus crejeesite · jeesite | Medium4.3 | — | 0.6% | Aug 1, 2023 |
17Monitor | CVE-2023-38988No exploit | An issue in the delete function in the OaNotifyController class of jeesite v1.2.6 allows authenticated attackers to arbitrarily delete notifjeesite · jeesite | Medium4.3 | — | 0.5% | Jul 28, 2023 |
17Monitor | CVE-2023-38989No exploit | An issue in the delete function in the UserController class of jeesite v1.2.6 allows authenticated attackers to arbitrarily delete the Adminjeesite · jeesite · CWE-862 | Medium4.3 | — | 0.4% | Jul 31, 2023 |
8Monitor | CVE-2025-7763No exploit | thinkgem JeeSite Site Controller SiteController.java select redirectjeesite · jeesite · CWE-601 | Low2.1 | — | 0.4% | Jul 17, 2025 |
8Monitor | CVE-2025-7785No exploit | thinkgem JeeSite SsoController.java sso redirectjeesite · jeesite · CWE-601 | Low2.1 | — | 0.4% | Jul 18, 2025 |
8Monitor | CVE-2025-9796No exploit | thinkgem JeeSite EncodeUtils.java decodeUrl2 cross site scriptingjeesite · jeesite · CWE-79 | Low2.0 | — | 0.4% | Sep 1, 2025 |
8Monitor | CVE-2025-7759No exploit | thinkgem JeeSite UEditor Image Grabber ActionEnter.java server-side request forgeryjeesite · jeesite · CWE-918 | Low2.1 | — | 0.3% | Jul 17, 2025 |
8Monitor | CVE-2025-7865No exploit | thinkgem JeeSite XSS Filter EncodeUtils.java xssFilter cross site scriptingjeesite · jeesite · CWE-79 | Low2.0 | — | 0.3% | Jul 20, 2025 |
8Monitor | CVE-2025-7864No exploit | thinkgem JeeSite FileUploadController.java upload unrestricted uploadjeesite · jeesite · CWE-284 | Low2.1 | — | 0.3% | Jul 19, 2025 |
5Monitor | CVE-2026-3405No exploit | thinkgem JeeSite Connection path traversaljeesite · jeesite · CWE-22 | Low1.3 | — | 0.9% | Mar 1, 2026 |
5Monitor | CVE-2026-3404No exploit | thinkgem JeeSite Endpoint CasOutHandler.java xml external entity referencejeesite · jeesite · CWE-610 | Low1.3 | — | 0.5% | Mar 1, 2026 |
- CVE-2020-1922939Monitor
Jeesite 1.2.7 uses the apache shiro version 1.2.3 affected by CVE-2016-4437.
CriticalCVSS 9.8No exploitEPSS 1%jeesite · jeesiteApr 5, 2022
- CVE-2023-3460139Monitor
Jeesite before commit 10742d3 was discovered to contain a SQL injection vulnerability via the component ${businessTable} at /act/ActDao.xml.
CriticalCVSS 9.8No exploitEPSS 1%jeesite · jeesiteJun 22, 2023
- CVE-2024-811227Monitor
thinkgem JeeSite Cookie login cross site scripting
MediumCVSS 6.9No exploitEPSS 0%jeesite · jeesiteAug 23, 2024
- CVE-2019-101020226Monitor
Jeesite 1.2.7 is affected by: XML External Entity (XXE).
MediumCVSS 6.5No exploitEPSS 1%jeesite · jeesiteJul 23, 2019
- CVE-2019-101020126Monitor
Jeesite 1.2.7 is affected by: SQL Injection.
MediumCVSS 6.5No exploitEPSS 1%jeesite · jeesiteJul 23, 2019
- CVE-2025-518621Monitor
thinkgem JeeSite URI Scheme form ResourceLoader.getResource server-side request forgery
MediumCVSS 5.3No exploitEPSS 0%jeesite · jeesiteMay 26, 2025
- CVE-2023-3899121Monitor
An issue in the delete function in the ActModelController class of jeesite v1.2.6 allows authenticated attackers to arbitrarily delete model
MediumCVSS 5.4No exploitEPSS 0%jeesite · jeesiteAug 3, 2023
- CVE-2025-786320Monitor
thinkgem JeeSite ServletUtils.java redirectUrl
MediumCVSS 5.1No exploitEPSS 0%jeesite · jeesiteJul 19, 2025
- CVE-2023-3899017Monitor
An issue in the delete function in the MenuController class of jeesite v1.2.6 allows authenticated attackers to arbitrarily delete menus cre
MediumCVSS 4.3No exploitEPSS 1%jeesite · jeesiteAug 1, 2023
- CVE-2023-3898817Monitor
An issue in the delete function in the OaNotifyController class of jeesite v1.2.6 allows authenticated attackers to arbitrarily delete notif
MediumCVSS 4.3No exploitEPSS 0%jeesite · jeesiteJul 28, 2023
- CVE-2023-3898917Monitor
An issue in the delete function in the UserController class of jeesite v1.2.6 allows authenticated attackers to arbitrarily delete the Admin
MediumCVSS 4.3No exploitEPSS 0%jeesite · jeesiteJul 31, 2023
- CVE-2025-77638Monitor
thinkgem JeeSite Site Controller SiteController.java select redirect
LowCVSS 2.1No exploitEPSS 0%jeesite · jeesiteJul 17, 2025
- CVE-2025-77858Monitor
thinkgem JeeSite SsoController.java sso redirect
LowCVSS 2.1No exploitEPSS 0%jeesite · jeesiteJul 18, 2025
- CVE-2025-97968Monitor
thinkgem JeeSite EncodeUtils.java decodeUrl2 cross site scripting
LowCVSS 2.0No exploitEPSS 0%jeesite · jeesiteSep 1, 2025
- CVE-2025-77598Monitor
thinkgem JeeSite UEditor Image Grabber ActionEnter.java server-side request forgery
LowCVSS 2.1No exploitEPSS 0%jeesite · jeesiteJul 17, 2025
- CVE-2025-78658Monitor
thinkgem JeeSite XSS Filter EncodeUtils.java xssFilter cross site scripting
LowCVSS 2.0No exploitEPSS 0%jeesite · jeesiteJul 20, 2025
- CVE-2025-78648Monitor
thinkgem JeeSite FileUploadController.java upload unrestricted upload
LowCVSS 2.1No exploitEPSS 0%jeesite · jeesiteJul 19, 2025
- CVE-2026-34055Monitor
thinkgem JeeSite Connection path traversal
LowCVSS 1.3No exploitEPSS 1%jeesite · jeesiteMar 1, 2026
- CVE-2026-34045Monitor
thinkgem JeeSite Endpoint CasOutHandler.java xml external entity reference
LowCVSS 1.3No exploitEPSS 1%jeesite · jeesiteMar 1, 2026