J2eefast is a web application framework whose vulnerability profile, despite a narrow product footprint, reaches a prominence in the landscape disproportionate to its exposure count, reflecting deep integration in legacy and current web deployments. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and concentrate in a pair of durable, high-impact application-layer weakness classes: SQL injection and cross-site scripting, both endemic to web request-handling and data-rendering paths in web frameworks. These recurring flaws reflect the parsing and output-encoding demands inherent to frameworks that process untrusted user input and generate dynamic web content. Defenders should inventory and prioritize patching of J2eefast instances, treating disclosed flaws as high-consequence until remediated; current severity, exploitation status, and detailed exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by J2eefast over time
Signals from CVEs in this vendor scope (21 CVEs).
21 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-28890CRITICAL J2eeFAST 2.2.1 allows remote attackers to perform SQL injection via the (1) compId parameter to fast/sys/user/list, (2) deptId parameter to fast/sys/role/list, or (3) roleId parame | Aug 12, 2021 | 9.8 | 28 | NO | NO |
CVE-2024-33155CRITICAL J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the getDeptList() function. | May 7, 2024 | 9.8 | 27 | NO | NO |
CVE-2024-33153CRITICAL J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the commentList() function. | May 7, 2024 | 9.8 | 27 | NO | NO |
CVE-2024-45944CRITICAL In J2eeFAST <=2.7, the backend function has unsafe filtering, which allows an attacker to trigger certain sensitive functions resulting in arbitrary code execution. | Oct 18, 2024 | 9.8 | 26 | NO | NO |
CVE-2024-35091CRITICAL J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function in SysTenantMapper.xml. | May 23, 2024 | 9.8 | 26 | NO | NO |
CVE-2024-35086CRITICAL J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function in BpmTaskFromMapper.xml . | May 23, 2024 | 9.8 | 26 | NO | NO |
CVE-2024-35084CRITICAL J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function in SysMsgPushMapper.xml. | May 23, 2024 | 9.8 | 26 | NO | NO |
CVE-2024-33164CRITICAL J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the authUserList() function. | May 7, 2024 | 9.8 | 26 | NO | NO |
CVE-2024-35083HIGH J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function in SysLoginInfoMapper.xml. | May 23, 2024 | 8.8 | 24 | NO | NO |
CVE-2024-33147HIGH J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the authRoleList function. | May 7, 2024 | 8.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (21 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by J2eefast.
Media articles that mention a CVE ID that affects a product developed by J2eefast — matched by CVE ID, not by vendor name.