Skip to main content

Vendor/product archive

jishenghua / jsherp CVEs

Beta · best-effort

26 CVEs tagged to jishenghua / jsherp9 Critical, 4 High, 5 Medium, 8 Low, 0 Unrated.

CVE-2026-1588

Published Jan 29, 2026

A vulnerability was found in jishenghua jshERP up to 3.6. The impacted element is the function install of the file /jshERP-boot/plugin/installByPath of the component com.gitee.sta…

CVSS 2.0 · Low
evidence mentions
5
Buzz score
24.4
Vendor/product tagsBeta · best-effort

CVE-2026-1549

Published Jan 28, 2026

A vulnerability was identified in jishenghua jshERP up to 3.6. Affected by this vulnerability is an unknown functionality of the file /jshERP-boot/plugin/uploadPluginConfigFile of…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
26.0
Vendor/product tagsBeta · best-effort

CVE-2026-1546

Published Jan 28, 2026

A security vulnerability has been detected in jishenghua jshERP up to 3.6. The impacted element is the function getBillItemByParam of the file /jshERP-boot/depotItem/importItemExc…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
26.0
Vendor/product tagsBeta · best-effort

CVE-2025-67344

Published Dec 12, 2025

jshERP v3.5 and earlier is affected by a stored Cross Site Scripting (XSS) vulnerability via the /msg/add endpoint.

CVSS 4.6 · Medium
evidence mentions
1
Buzz score
16.4
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-67341

Published Dec 12, 2025

jshERP versions 3.5 and earlier are affected by a stored XSS vulnerability. This vulnerability allows attackers to upload PDF files containing XSS payloads. Additionally, these PD…

CVSS 4.6 · Medium
evidence mentions
1
Buzz score
16.4
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-51746

Published Nov 25, 2025

An issue was discovered in jishenghua JSH_ERP 2.3.1. The /serialNumber/addSerialNumber endpoint is vulnerable to fastjson deserialization attacks.

CVSS 9.8 · Critical
evidence mentions
4
Buzz score
27.6
Vendor/product tagsBeta · best-effort

CVE-2025-51745

Published Nov 25, 2025

An issue was discovered in jishenghua JSH_ERP 2.3.1. The /role/addcan endpoint is vulnerable to fastjson deserialization attacks.

CVSS 9.8 · Critical
evidence mentions
4
Buzz score
27.6
Vendor/product tagsBeta · best-effort

CVE-2025-51744

Published Nov 25, 2025

An issue was discovered in jishenghua JSH_ERP 2.3.1. The /user/addUser endpoint is vulnerable to fastjson deserialization attacks.

CVSS 9.8 · Critical
evidence mentions
4
Buzz score
27.6
Vendor/product tagsBeta · best-effort

CVE-2025-51743

Published Nov 25, 2025

An issue was discovered in jishenghua JSH_ERP 2.3.1. The /materialCategory/addMaterialCategory endpoint is vulnerable to fastjson deserialization attacks.

CVSS 9.8 · Critical
evidence mentions
4
Buzz score
27.6
Vendor/product tagsBeta · best-effort

CVE-2025-51742

Published Nov 25, 2025

An issue was discovered in jishenghua JSH_ERP 2.3.1. The /material/getMaterialEnableSerialNumberList endpoint passes the search query parameter directly to parseObject(), introduc…

CVSS 9.8 · Critical
evidence mentions
4
Buzz score
27.6
Vendor/product tagsBeta · best-effort

CVE-2025-60800

Published Oct 28, 2025

Incorrect access control in the /jshERP-boot/user/info interface of jshERP up to commit 90c411a allows attackers to access sensitive information via a crafted GET request.

CVSS 7.5 · High
evidence mentions
1
Buzz score
16.4
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-60801

Published Oct 24, 2025

jshERP up to commit fbda24da was discovered to contain an unauthenticated remote code execution (RCE) vulnerability via the jsh_erp function.

CVSS 8.2 · High
evidence mentions
2
Buzz score
22.0
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-55371

Published Aug 21, 2025

Incorrect access control in the component /controller/PersonController.java of jshERP v3.5 allows unauthorized attackers to obtain all the information of the handler by executing…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
25.0
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-55370

Published Aug 21, 2025

Incorrect access control in the component \controller\ResourceController.java of jshERP v3.5 allows unauthorized attackers to obtain all the corresponding ID data by modifying the…

CVSS 8.8 · High
evidence mentions
2
Buzz score
20.5
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-55368

Published Aug 21, 2025

Incorrect access control in the component \controller\RoleController.java of jshERP v3.5 allows unauthorized attackers to arbitrarily modify the supplier status under any account.

CVSS 8.8 · High
evidence mentions
2
Buzz score
25.0
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-55367

Published Aug 21, 2025

Incorrect access control in the component \controller\SupplierController.java of jshERP v3.5 allows unauthorized attackers to arbitrarily modify the supplier status under any acco…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
25.0
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-55366

Published Aug 21, 2025

Incorrect access control in the component \controller\UserController.java of jshERP v3.5 allows attackers to arbitrarily reset user account passwords and execute a horizontal priv…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
25.0
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-8840

Published Aug 11, 2025

A vulnerability was determined in jshERP up to 3.5. Affected is an unknown function of the file /jshERP-boot/user/deleteBatch of the component Endpoint. The manipulation of the ar…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-8839

Published Aug 11, 2025

A vulnerability was found in jshERP up to 3.5. This issue affects some unknown processing of the file /jshERP-boot/user/addUser of the component Endpoint. The manipulation leads t…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-7948

Published Jul 22, 2025

A vulnerability classified as problematic was found in jshERP up to 3.5. Affected by this vulnerability is an unknown functionality of the file /jshERP-boot/user/updatePwd. The ma…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-7947

Published Jul 22, 2025

A vulnerability classified as critical has been found in jshERP up to 3.5. Affected is an unknown function of the file /user/delete of the component Account Handler. The manipulat…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-7566

Published Jul 14, 2025

A vulnerability has been found in jshERP up to 3.5 and classified as critical. This vulnerability affects the function exportExcelByParam of the file /src/main/java/com/jsh/erp/co…

CVSS 2.0 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-24003

Published Feb 8, 2024

jshERP v3.3 is vulnerable to SQL Injection. The com.jsh.erp.controller.DepotHeadController: com.jsh.erp.utils.BaseResponseInfo findInOutMaterialCount() function of jshERP does not…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-24004

Published Feb 7, 2024

jshERP v3.3 is vulnerable to SQL Injection. The com.jsh.erp.controller.DepotHeadController: com.jsh.erp.utils.BaseResponseInfo findInOutDetail() function of jshERP does not filter…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-24002

Published Feb 7, 2024

jshERP v3.3 is vulnerable to SQL Injection. The com.jsh.erp.controller.MaterialController: com.jsh.erp.utils.BaseResponseInfo getListWithStock() function of jshERP does not filter…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-25 of 26 CVEsPage 1 of 2