Search
Search Results (43 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-108656 | 1 Jeecg | 2 Jeecg-boot, Jeecg Boot | 2026-10-11 | 4.3 Medium |
| JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysTenantController GET /sys/tenant/getTenantPackApplyUsers endpoint that allows any authenticated user to read tenant administrator applications. Low-privileged attackers can iterate the tenantId parameter to retrieve pending applicants' usernames, real names, phone numbers and departments for any tenant. | ||||
| CVE-2026-108614 | 1 Jeecg | 2 Jeecg-boot, Jeecg Boot | 2026-10-10 | 4.3 Medium |
| JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the AiragExtDataController exportXls handler that allows any authenticated user to export AI evaluator data. Low-privileged attackers can request /airag/extData/exportXls to download every user's airag_ext_data evaluator definitions and test-tracking records as an Excel workbook. | ||||
| CVE-2026-108616 | 2 Jeecg, Jeecgboot | 3 Jeecg-boot, Jeecg Boot, Jeecgboot | 2026-10-10 | 5.4 Medium |
| JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the AiragExtDataController deleteBatch handler that allows any authenticated user to delete AI evaluator records. Low-privileged attackers can send comma-separated ids to DELETE /airag/extData/deleteBatch, which lacks owner or tenant checks, deleting other users' evaluator and test-tracking records. | ||||