E Cology
Vendor:
First CVE: Apr 30, 2019 · Active for 7 years
11
Total CVEs
More Total CVEs than 90% of tracked products
2.2
Avg CVEs / Year
Higher CVE frequency than 76% of tracked products
8.7
Avg CVSS
Higher Avg CVSS than 78% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact E Cology over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 30, 2019
7 years ago
Most Recent CVE
Apr 7, 2026
112 days ago
CVE Severity & Scoring
E Cology11 CVEs
18%
27%
55%
All CVEs353,240 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network11 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low11 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None10 (90.9%)
Unknown0 (0.0%)
Required1 (9.1%)
Privileges Required
Low2 (18.2%)
High0 (0.0%)
None9 (81.8%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-22679CRITICAL Weaver (Fanwei) E-cology 10.0 versions prior to 20260312 contain an unauthenticated remote code execution vulnerability in the /papi/esearch/data/devops/dubboApi/debug/method endpo | Apr 7, 2026 | 9.8 | 52 | NO | NO |
CVE-2025-34038HIGH A SQL injection vulnerability exists in Weaver E-cology 8.0 via the getdata.jsp endpoint. The application directly passes unsanitized user input from the sql parameter into a datab | Jun 24, 2025 | 7.5 | 32 | NO | YES |
CVE-2024-48069CRITICAL A vulnerability was found in Weaver E-cology allows attackers use race conditions to bypass security mechanisms to upload malicious files and control server privileges | Nov 19, 2024 | 9.8 | 29 | NO | NO |
CVE-2023-51892CRITICAL An issue in weaver e-cology v.10.0.2310.01 allows a remote attacker to execute arbitrary code via a crafted script to the FrameworkShellController component. | Jan 20, 2024 | 9.8 | 29 | NO | NO |
CVE-2023-3793CRITICAL A vulnerability was found in Weaver e-cology. It has been rated as critical. This issue affects some unknown processing of the file filelFileDownloadForOutDoc.class of the componen | Jul 20, 2023 | 9.8 | 29 | NO | NO |
CVE-2024-48072CRITICAL Weaver Ecology v9.* was discovered to contain a SQL injection vulnerability via the component /mobilemode/Action.jsp?invoker=com.weaver.formmodel.mobile.mec.servlet.MECAction&actio | Nov 19, 2024 | 9.8 | 25 | NO | NO |
CVE-2024-48070CRITICAL An issue in Weaver E-cology v. attackers construct special requests to insert remote malicious code and to trigger malicious code execution, and control server privileges | Nov 19, 2024 | 9.8 | 25 | NO | NO |
CVE-2023-2806HIGH A vulnerability classified as problematic was found in Weaver e-cology up to 9.0. Affected by this vulnerability is the function RequestInfoByXml of the component API. The manipula | May 19, 2023 | 8.8 | 23 | NO | NO |
CVE-2024-7704HIGH A vulnerability was found in Weaver e-cology 8. It has been classified as problematic. Affected is an unknown function of the file /cloudstore/ecode/setup/ecology_dev.zip of the co | Aug 12, 2024 | 7.5 | 21 | NO | NO |
CVE-2019-10272MEDIUM An issue was discovered in Weaver e-cology 9.0. There is a CRLF Injection vulnerability via the /workflow/request/ViewRequestForwardSPA.jsp isintervenor parameter, as demonstrated | Apr 30, 2019 | 6.1 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (11 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
9.1% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (11 CVEs).
Media Mentions
Signals from CVEs in this product scope (11 CVEs).
Top CNAs Publishing CVEs For E Cology
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 9.0 | 6 | 8.5 | 0.7% | 0 | 0 |
| 8.0 | 2 | 8.7 | 0.6% | 0 | 0 |
| 10.0.2310.01 | 1 | 9.8 | 1.0% | 0 | 0 |