Vulnerabilities (CVE)

Filtered by vendor Jeecg Subscribe
Filtered by product Jeecg
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-49442 1 Jeecg 1 Jeecg 2024-01-10 N/A 9.8 CRITICAL
Deserialization of Untrusted Data in jeecgFormDemoController in JEECG 4.0 and earlier allows attackers to run arbitrary code via crafted POST request.
CVE-2020-20948 1 Jeecg 1 Jeecg 2022-01-07 5.0 MEDIUM 7.5 HIGH
An arbitrary file download vulnerability in jeecg v3.8 allows attackers to access sensitive files via modification of the "localPath" variable.