← Back

J2eefast

j2eefast

21 CVEs • 1 product

Products (1)

Click to collapse
Toggle
J2eefast
j2eefast

CVEs (21)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1J2eefast
1J2eefast
Jun 17, 2026
Oct 18, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In J2eeFAST <=2.7, the backend function has unsafe filtering, which allows an attacker to trigger certain sensitive functions resulting in arbitrary code execution.
1J2eefast
1J2eefast
Jun 17, 2026
May 23, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function in SysTenantMapper.xml.
1J2eefast
1J2eefast
Jun 17, 2026
May 23, 2024
N/A· v4
8.2 HIGH· v3
N/A· v2
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function in SysUreportFileMapper.xml.
1J2eefast
1J2eefast
Jun 17, 2026
May 23, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function in BpmTaskFromMapper.xml .
1J2eefast
1J2eefast
Jun 17, 2026
May 23, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function in ProcessDefinitionMapper.xml.
1J2eefast
1J2eefast
Jun 17, 2026
May 23, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function in SysMsgPushMapper.xml.
1J2eefast
1J2eefast
Jun 17, 2026
May 23, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function in SysLoginInfoMapper.xml.
1J2eefast
1J2eefast
Jun 17, 2026
May 23, 2024
N/A· v4
6.3 MEDIUM· v3
N/A· v2
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function in SysOperLogMapper.xml.
1J2eefast
1J2eefast
Jun 17, 2026
May 7, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the authUserList() function.
1J2eefast
1J2eefast
Jun 17, 2026
May 7, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the unallocatedList() function.
1J2eefast
1J2eefast
Jun 17, 2026
May 7, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the getDeptList() function.
1J2eefast
1J2eefast
Jun 17, 2026
May 7, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the commentList() function.
1J2eefast
1J2eefast
Jun 17, 2026
May 7, 2024
N/A· v4
8.1 HIGH· v3
N/A· v2
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the myProcessList function.
1J2eefast
1J2eefast
Jun 17, 2026
May 7, 2024
N/A· v4
7.3 HIGH· v3
N/A· v2
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the list function.
1J2eefast
1J2eefast
Jun 17, 2026
May 7, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the authRoleList function.
1J2eefast
1J2eefast
Jun 17, 2026
May 7, 2024
N/A· v4
9.1 CRITICAL· v3
N/A· v2
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the export function.
1J2eefast
1J2eefast
Jun 17, 2026
May 7, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the findApplyedTasksPage function in BpmTaskMapper.xml.
1J2eefast
1J2eefast
Jun 17, 2026
May 7, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the sql_filter parameter in the findpage function.
1J2eefast
1J2eefast
Jun 17, 2026
May 2, 2023
N/A· v4
5.4 MEDIUM· v3
4.0 MEDIUM· v2
A vulnerability was found in Dromara J2eeFAST up to 2.6.0. It has been classified as problematic. Affected is an unknown function of the component Announcement Handler. The manipulation of the argument 系统工具/公告管理 leads to...Show more
A vulnerability was found in Dromara J2eeFAST up to 2.6.0. It has been classified as problematic. Affected is an unknown function of the component Announcement Handler. The manipulation of the argument 系统工具/公告管理 leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The name of the patch is 7a9e1a00e3329fdc0ae05f7a8257cce77037134d. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-227868.Show less
1J2eefast
1J2eefast
Jun 17, 2026
May 2, 2023
N/A· v4
5.4 MEDIUM· v3
4.0 MEDIUM· v2
A vulnerability was found in Dromara J2eeFAST up to 2.6.0 and classified as problematic. This issue affects some unknown processing of the component System Message Handler. The manipulation of the argument 主题 leads to cr...Show more
A vulnerability was found in Dromara J2eeFAST up to 2.6.0 and classified as problematic. This issue affects some unknown processing of the component System Message Handler. The manipulation of the argument 主题 leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The patch is named 7a9e1a00e3329fdc0ae05f7a8257cce77037134d. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-227867.Show less