Jeecg is a Chinese enterprise application framework and development platform with a narrow product footprint centered on Jeecg Boot and related business intelligence and reporting tools, but its vulnerabilities are tracked at a prominence level exceeding typical vendors in the landscape. Vulnerabilities affecting the vendor skew strongly toward critical severity and frequently acquire public exploit code, reflecting both the framework's exposure as a development platform for web applications and the appeal of its flaws to security researchers and tool developers. The exposure recurs through weakness classes including SQL injection, improper authorization and privilege assignment, and deserialization of untrusted data, which are characteristic of Java-based enterprise frameworks and their integration of user-supplied input and object handling. Defenders should prioritize assessment of internal and internet-facing deployments of Jeecg Boot applications and treat the vendor's advisories as high-urgency for remediation; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Jeecg over time
Signals from CVEs in this vendor scope (72 CVEs).
72 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-38992CRITICAL jeecg-boot v3.5.1 was discovered to contain a SQL injection vulnerability via the title parameter at /sys/dict/loadTreeData. | Jul 28, 2023 | 9.8 | 76 | NO | YES |
CVE-2024-48307CRITICAL JeecgBoot v3.7.1 was discovered to contain a SQL injection vulnerability via the component /onlDragDatasetHead/getTotalData. | Oct 31, 2024 | 9.8 | 63 | NO | YES |
CVE-2023-1454CRITICAL A vulnerability classified as critical has been found in jeecg-boot 3.5.0. This affects an unknown part of the file jmreport/qurestSql. The manipulation of the argument apiSelectId | Mar 17, 2023 | 9.8 | 61 | NO | YES |
CVE-2023-49442CRITICAL Deserialization of Untrusted Data in jeecgFormDemoController in JEECG 4.0 and earlier allows attackers to run arbitrary code via crafted POST request. | Jan 3, 2024 | 9.8 | 47 | NO | NO |
CVE-2023-4450CRITICAL A vulnerability was found in jeecgboot JimuReport up to 1.6.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Templat | Aug 21, 2023 | 9.8 | 47 | NO | YES |
CVE-2023-34659CRITICAL jeecg-boot 3.5.0 and 3.5.1 have a SQL injection vulnerability the id parameter of the /jeecg-boot/jmreport/show interface. | Jun 16, 2023 | 9.8 | 44 | NO | YES |
CVE-2021-37305HIGH An Insecure Permissions issue in jeecg-boot 2.4.5 and earlier allows remote attackers to gain escalated privilege and view sensitive information via api uri: /sys/user/querySysUser | Feb 3, 2023 | 7.5 | 39 | NO | YES |
CVE-2021-37304HIGH An Insecure Permissions issue in jeecg-boot 2.4.5 allows unauthenticated remote attackers to gain escalated privilege and view sensitive information via the httptrace interface. | Feb 3, 2023 | 7.5 | 35 | NO | YES |
CVE-2025-66913CRITICAL JimuReport thru version 2.1.3 is vulnerable to remote code execution when processing user-controlled H2 JDBC URLs. The application passes the attacker-supplied JDBC URL directly to | Jan 8, 2026 | 9.8 | 34 | NO | NO |
CVE-2025-8963CRITICAL A vulnerability was determined in jeecgboot JimuReport up to 2.1.1. Affected by this issue is some unknown functionality of the file /drag/onlDragDataSource/testConnection of the c | Aug 14, 2025 | 9.8 | 34 | NO | NO |
Signals from CVEs in this vendor scope (72 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Jeecg.
Media articles that mention a CVE ID that affects a product developed by Jeecg — matched by CVE ID, not by vendor name.