Datax Web Project maintains a focused web application product that, despite a narrow scope, has attracted security attention from the research community. The observed vulnerability surface centers on the web application itself, and defenders should monitor this vendor's security advisories for issues affecting deployed instances; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Datax Web Project over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-7116CRITICAL A vulnerability, which was classified as critical, has been found in WeiYe-Jing datax-web 2.1.2. Affected by this issue is some unknown functionality of the file /api/log/killJob o | Dec 27, 2023 | 9.8 | 42 | NO | YES |
CVE-2022-46478CRITICAL The RPC interface in datax-web v1.0.0 and v2.0.0 to v2.1.2 contains no permission checks by default which allows attackers to execute arbitrary commands via crafted Hessian seriali | Jan 13, 2023 | 9.8 | 31 | NO | NO |
CVE-2025-13251HIGH A flaw has been found in WeiYe-Jing datax-web up to 2.1.2. Affected is an unknown function. Executing manipulation can lead to sql injection. The attack may be launched remotely. T | Nov 16, 2025 | 8.8 | 28 | NO | NO |
CVE-2025-13250HIGH A vulnerability was detected in WeiYe-Jing datax-web up to 2.1.2. This impacts the function remove/update/pause/start/triggerJob of the component Job Handler. Performing manipulati | Nov 16, 2025 | 8.8 | 27 | NO | NO |
CVE-2024-12358HIGH A vulnerability was found in WeiYe-Jing datax-web 2.1.1. It has been classified as critical. This affects an unknown part of the file /api/job/add/. The manipulation of the argumen | Dec 9, 2024 | 8.8 | 26 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Datax Web Project.
Media articles that mention a CVE ID that affects a product developed by Datax Web Project — matched by CVE ID, not by vendor name.