jishenghua CVE Vulnerabilities & CVE List (26)

Products (CPE): — CVEs: 26

jishenghua vulnerability overview

Aggregates CVE and security vulnerability intelligence across all jishenghua-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Disclosed issues often relate to vendor risk path handling, vendor risk sql injection, and vendor risk cross-site scripting; exposure may include vendor impact data exposure in vendor surface production workloads contexts.

Vulnerability distribution trend (last 24 months)

Showing 120 of 26 CVEs
«« First « Prev Page 1 / 2 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2026-1588 A vulnerability was found in jishenghua jshERP up to 3.6. The impacted element is the function install of the file /jshERP-boot/plugin/installByPath of the component com.gitee.starblues.integration.operator.DefaultPluginOperator. The manipulation of the argument path results in path traversal. It is possible to launch the attack remotely. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet. [email protected] 2.0 0.59% 2026-01-29 2026-06-17
CVE-2026-1549 A vulnerability was identified in jishenghua jshERP up to 3.6. Affected by this vulnerability is an unknown functionality of the file /jshERP-boot/plugin/uploadPluginConfigFile of the component PluginController. Such manipulation of the argument configFile leads to path traversal. The attack may be launched remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet. [email protected] 2.1 0.47% 2026-01-28 2026-06-17
CVE-2026-1546 A security vulnerability has been detected in jishenghua jshERP up to 3.6. The impacted element is the function getBillItemByParam of the file /jshERP-boot/depotItem/importItemExcel of the component com.jsh.erp.datasource.mappers.DepotItemMapperEx. The manipulation of the argument barCodes leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has no [email protected] 2.1 0.34% 2026-01-28 2026-06-17
CVE-2025-67344 jshERP v3.5 and earlier is affected by a stored Cross Site Scripting (XSS) vulnerability via the /msg/add endpoint. [email protected] 4.6 0.14% 2025-12-12 2026-06-17
CVE-2025-67341 jshERP versions 3.5 and earlier are affected by a stored XSS vulnerability. This vulnerability allows attackers to upload PDF files containing XSS payloads. Additionally, these PDF files can be accessed via static URLs, making them accessible to all users. [email protected] 4.6 0.14% 2025-12-12 2026-06-17
CVE-2025-51746 An issue was discovered in jishenghua JSH_ERP 2.3.1. The /serialNumber/addSerialNumber endpoint is vulnerable to fastjson deserialization attacks. [email protected] 9.8 0.39% 2025-11-25 2026-06-17
CVE-2025-51745 An issue was discovered in jishenghua JSH_ERP 2.3.1. The /role/addcan endpoint is vulnerable to fastjson deserialization attacks. [email protected] 9.8 0.39% 2025-11-25 2026-06-17
CVE-2025-51744 An issue was discovered in jishenghua JSH_ERP 2.3.1. The /user/addUser endpoint is vulnerable to fastjson deserialization attacks. [email protected] 9.8 0.39% 2025-11-25 2026-06-17
CVE-2025-51743 An issue was discovered in jishenghua JSH_ERP 2.3.1. The /materialCategory/addMaterialCategory endpoint is vulnerable to fastjson deserialization attacks. [email protected] 9.8 0.39% 2025-11-25 2026-06-17
CVE-2025-51742 An issue was discovered in jishenghua JSH_ERP 2.3.1. The /material/getMaterialEnableSerialNumberList endpoint passes the search query parameter directly to parseObject(), introducing a Fastjson deserialization vulnerability that can lead to RCE via JDBC payloads. [email protected] 9.8 0.40% 2025-11-25 2026-06-17
CVE-2025-60800 Incorrect access control in the /jshERP-boot/user/info interface of jshERP up to commit 90c411a allows attackers to access sensitive information via a crafted GET request. [email protected] 7.5 0.26% 2025-10-28 2026-06-17
CVE-2025-60801 jshERP up to commit fbda24da was discovered to contain an unauthenticated remote code execution (RCE) vulnerability via the jsh_erp function. [email protected] 8.2 0.39% 2025-10-24 2026-06-17
CVE-2025-55371 Incorrect access control in the component /controller/PersonController.java of jshERP v3.5 allows unauthorized attackers to obtain all the information of the handler by executing the getAllList method. [email protected] 5.3 0.33% 2025-08-21 2026-07-04
CVE-2025-55370 Incorrect access control in the component \controller\ResourceController.java of jshERP v3.5 allows unauthorized attackers to obtain all the corresponding ID data by modifying the ID value. [email protected] 8.8 0.40% 2025-08-21 2026-07-04
CVE-2025-55368 Incorrect access control in the component \controller\RoleController.java of jshERP v3.5 allows unauthorized attackers to arbitrarily modify the supplier status under any account. [email protected] 8.8 0.40% 2025-08-21 2026-07-04
CVE-2025-55367 Incorrect access control in the component \controller\SupplierController.java of jshERP v3.5 allows unauthorized attackers to arbitrarily modify the supplier status under any account. [email protected] 5.3 0.33% 2025-08-21 2026-07-04
CVE-2025-55366 Incorrect access control in the component \controller\UserController.java of jshERP v3.5 allows attackers to arbitrarily reset user account passwords and execute a horizontal privilege escalation attack. [email protected] 5.3 0.33% 2025-08-21 2026-07-04
CVE-2025-8840 A vulnerability was determined in jshERP up to 3.5. Affected is an unknown function of the file /jshERP-boot/user/deleteBatch of the component Endpoint. The manipulation of the argument ids leads to improper authorization. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Different than CVE-2025-7947. [email protected] 2.1 0.40% 2025-08-11 2026-06-17
CVE-2025-8839 A vulnerability was found in jshERP up to 3.5. This issue affects some unknown processing of the file /jshERP-boot/user/addUser of the component Endpoint. The manipulation leads to improper authorization. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. [email protected] 2.1 0.31% 2025-08-11 2026-06-17
CVE-2025-7948 A vulnerability classified as problematic was found in jshERP up to 3.5. Affected by this vulnerability is an unknown functionality of the file /jshERP-boot/user/updatePwd. The manipulation leads to weak password recovery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. [email protected] 2.1 0.36% 2025-07-21 2026-06-17
«« First « Prev Page 1 / 2 Next »
cvelogic Threat Intelligence