Skip to content
Noroxi

Jeesite records

19 published records for vendor jeesite.

All records

19 records
  • Jeesite 1.2.7 uses the apache shiro version 1.2.3 affected by CVE-2016-4437.

    CriticalCVSS 9.8No exploitEPSS 1%

    jeesite · jeesiteApr 5, 2022

  • Jeesite before commit 10742d3 was discovered to contain a SQL injection vulnerability via the component ${businessTable} at /act/ActDao.xml.

    CriticalCVSS 9.8No exploitEPSS 1%

    jeesite · jeesiteJun 22, 2023

  • CVE-2024-8112
    27Monitor

    thinkgem JeeSite Cookie login cross site scripting

    MediumCVSS 6.9No exploitEPSS 0%

    jeesite · jeesiteAug 23, 2024

  • Jeesite 1.2.7 is affected by: XML External Entity (XXE).

    MediumCVSS 6.5No exploitEPSS 1%

    jeesite · jeesiteJul 23, 2019

  • Jeesite 1.2.7 is affected by: SQL Injection.

    MediumCVSS 6.5No exploitEPSS 1%

    jeesite · jeesiteJul 23, 2019

  • CVE-2025-5186
    21Monitor

    thinkgem JeeSite URI Scheme form ResourceLoader.getResource server-side request forgery

    MediumCVSS 5.3No exploitEPSS 0%

    jeesite · jeesiteMay 26, 2025

  • An issue in the delete function in the ActModelController class of jeesite v1.2.6 allows authenticated attackers to arbitrarily delete model

    MediumCVSS 5.4No exploitEPSS 0%

    jeesite · jeesiteAug 3, 2023

  • CVE-2025-7863
    20Monitor

    thinkgem JeeSite ServletUtils.java redirectUrl

    MediumCVSS 5.1No exploitEPSS 0%

    jeesite · jeesiteJul 19, 2025

  • An issue in the delete function in the MenuController class of jeesite v1.2.6 allows authenticated attackers to arbitrarily delete menus cre

    MediumCVSS 4.3No exploitEPSS 1%

    jeesite · jeesiteAug 1, 2023

  • An issue in the delete function in the OaNotifyController class of jeesite v1.2.6 allows authenticated attackers to arbitrarily delete notif

    MediumCVSS 4.3No exploitEPSS 0%

    jeesite · jeesiteJul 28, 2023

  • An issue in the delete function in the UserController class of jeesite v1.2.6 allows authenticated attackers to arbitrarily delete the Admin

    MediumCVSS 4.3No exploitEPSS 0%

    jeesite · jeesiteJul 31, 2023

  • thinkgem JeeSite Site Controller SiteController.java select redirect

    LowCVSS 2.1No exploitEPSS 0%

    jeesite · jeesiteJul 17, 2025

  • thinkgem JeeSite SsoController.java sso redirect

    LowCVSS 2.1No exploitEPSS 0%

    jeesite · jeesiteJul 18, 2025

  • thinkgem JeeSite EncodeUtils.java decodeUrl2 cross site scripting

    LowCVSS 2.0No exploitEPSS 0%

    jeesite · jeesiteSep 1, 2025

  • thinkgem JeeSite UEditor Image Grabber ActionEnter.java server-side request forgery

    LowCVSS 2.1No exploitEPSS 0%

    jeesite · jeesiteJul 17, 2025

  • thinkgem JeeSite XSS Filter EncodeUtils.java xssFilter cross site scripting

    LowCVSS 2.0No exploitEPSS 0%

    jeesite · jeesiteJul 20, 2025

  • thinkgem JeeSite FileUploadController.java upload unrestricted upload

    LowCVSS 2.1No exploitEPSS 0%

    jeesite · jeesiteJul 19, 2025

  • thinkgem JeeSite Connection path traversal

    LowCVSS 1.3No exploitEPSS 1%

    jeesite · jeesiteMar 1, 2026

  • thinkgem JeeSite Endpoint CasOutHandler.java xml external entity reference

    LowCVSS 1.3No exploitEPSS 1%

    jeesite · jeesiteMar 1, 2026