Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Jeecg

First CVE: Aug 6, 2021Active for: 5 yearsTotal CVEs: 72
63.3
VTI Score
TOP TARGET

Jeecg is a Chinese enterprise application framework and development platform with a narrow product footprint centered on Jeecg Boot and related business intelligence and reporting tools, but its vulnerabilities are tracked at a prominence level exceeding typical vendors in the landscape. Vulnerabilities affecting the vendor skew strongly toward critical severity and frequently acquire public exploit code, reflecting both the framework's exposure as a development platform for web applications and the appeal of its flaws to security researchers and tool developers. The exposure recurs through weakness classes including SQL injection, improper authorization and privilege assignment, and deserialization of untrusted data, which are characteristic of Java-based enterprise frameworks and their integration of user-supplied input and object handling. Defenders should prioritize assessment of internal and internet-facing deployments of Jeecg Boot applications and treat the vendor's advisories as high-urgency for remediation; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
72
Total CVEs
More Total CVEs than 99% of tracked vendors
3.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 91% of tracked vendors
7.7
Avg CVSS Score
Higher Avg CVSS Score than 73% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Jeecg over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 6, 2021
4 years ago
Most Recent CVE
Apr 1, 2026
114 days ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (72 CVEs).

72 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-38992CRITICAL
jeecg-boot v3.5.1 was discovered to contain a SQL injection vulnerability via the title parameter at /sys/dict/loadTreeData.
Jul 28, 20239.876NOYES
CVE-2024-48307CRITICAL
JeecgBoot v3.7.1 was discovered to contain a SQL injection vulnerability via the component /onlDragDatasetHead/getTotalData.
Oct 31, 20249.863NOYES
CVE-2023-1454CRITICAL
A vulnerability classified as critical has been found in jeecg-boot 3.5.0. This affects an unknown part of the file jmreport/qurestSql. The manipulation of the argument apiSelectId
Mar 17, 20239.861NOYES
CVE-2023-49442CRITICAL
Deserialization of Untrusted Data in jeecgFormDemoController in JEECG 4.0 and earlier allows attackers to run arbitrary code via crafted POST request.
Jan 3, 20249.847NONO
CVE-2023-4450CRITICAL
A vulnerability was found in jeecgboot JimuReport up to 1.6.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Templat
Aug 21, 20239.847NOYES
CVE-2023-34659CRITICAL
jeecg-boot 3.5.0 and 3.5.1 have a SQL injection vulnerability the id parameter of the /jeecg-boot/jmreport/show interface.
Jun 16, 20239.844NOYES
CVE-2021-37305HIGH
An Insecure Permissions issue in jeecg-boot 2.4.5 and earlier allows remote attackers to gain escalated privilege and view sensitive information via api uri: /sys/user/querySysUser
Feb 3, 20237.539NOYES
CVE-2021-37304HIGH
An Insecure Permissions issue in jeecg-boot 2.4.5 allows unauthenticated remote attackers to gain escalated privilege and view sensitive information via the httptrace interface.
Feb 3, 20237.535NOYES
CVE-2025-66913CRITICAL
JimuReport thru version 2.1.3 is vulnerable to remote code execution when processing user-controlled H2 JDBC URLs. The application passes the attacker-supplied JDBC URL directly to
Jan 8, 20269.834NONO
CVE-2025-8963CRITICAL
A vulnerability was determined in jeecgboot JimuReport up to 2.1.1. Affected by this issue is some unknown functionality of the file /drag/onlDragDataSource/testConnection of the c
Aug 14, 20259.834NONO
View all 72 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products72 CVEs
8%
28%
25%
39%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (1.4%)
Network71 (98.6%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low62 (86.1%)
High10 (13.9%)
Unknown0 (0.0%)
User Interaction
None69 (95.8%)
Unknown0 (0.0%)
Required3 (4.2%)
Privileges Required
Low30 (41.7%)
High1 (1.4%)
None41 (56.9%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (72 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
7 CVEs
9.7% of CVEs· 96th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Jeecg.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Jeecg — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Jeecg's Products

View all 2 CNAs →

Top CWEs