Anji Plus maintains a narrowly scoped reporting and business-intelligence product portfolio, with its vulnerability footprint concentrated in the AJ-Report platform. The vendor's disclosures reflect the typical input-handling and data-processing surface of web-facing reporting tools; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Anji Plus over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-7314CRITICAL anji-plus AJ-Report is affected by an authentication bypass vulnerability. A remote and unauthenticated attacker can append ";swagger-ui" to HTTP requests to bypass authentication | Aug 2, 2024 | 9.8 | 68 | NO | YES |
CVE-2024-5355CRITICAL A vulnerability, which was classified as critical, has been found in anji-plus AJ-Report up to 1.4.1. This issue affects the function IGroovyHandler. The manipulation leads to comm | May 26, 2024 | 9.8 | 31 | NO | NO |
CVE-2022-46973CRITICAL Report v0.9.8.6 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability. | Mar 3, 2023 | 9.8 | 30 | NO | NO |
CVE-2022-42983HIGH anji-plus AJ-Report 0.9.8.6 allows remote attackers to bypass login authentication by spoofing JWT Tokens. | Oct 17, 2022 | 8.8 | 28 | NO | NO |
CVE-2024-5356CRITICAL A vulnerability, which was classified as critical, was found in anji-plus AJ-Report up to 1.4.1. Affected is an unknown function of the file /dataSet/testTransform;swagger-ui. The | May 26, 2024 | 9.8 | 27 | NO | NO |
CVE-2024-5350CRITICAL A vulnerability was found in anji-plus AJ-Report up to 1.4.1. It has been classified as critical. Affected is the function pageList of the file /pageList. The manipulation of the a | May 25, 2024 | 9.8 | 27 | NO | NO |
CVE-2024-5352CRITICAL A vulnerability was found in anji-plus AJ-Report up to 1.4.1. It has been rated as critical. Affected by this issue is the function validationRules of the component com.anjiplus.te | May 26, 2024 | 9.8 | 26 | NO | NO |
CVE-2024-5351CRITICAL A vulnerability was found in anji-plus AJ-Report up to 1.4.1. It has been declared as critical. Affected by this vulnerability is the function getValueFromJs of the component Javas | May 26, 2024 | 9.8 | 26 | NO | NO |
CVE-2024-5353CRITICAL A vulnerability classified as critical has been found in anji-plus AJ-Report up to 1.4.1. This affects the function decompress of the component ZIP File Handler. The manipulation l | May 26, 2024 | 9.8 | 25 | NO | NO |
CVE-2024-5354MEDIUM A vulnerability classified as problematic was found in anji-plus AJ-Report up to 1.4.1. This vulnerability affects unknown code of the file /reportShare/detailByCode. The manipulat | May 26, 2024 | 6.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Anji Plus.
Media articles that mention a CVE ID that affects a product developed by Anji Plus — matched by CVE ID, not by vendor name.