Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 02 Jun 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 01 Jun 2026 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was determined in JeecgBoot up to 3.9.2. The affected element is the function WordUtil.addImage of the file /airag/word/edit. Executing a manipulation can lead to server-side request forgery. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. A fix is planned for the upcoming release. | |
| Title | JeecgBoot edit WordUtil.addImage server-side request forgery | |
| First Time appeared |
Jeecgboot
Jeecgboot jeecgboot |
|
| Weaknesses | CWE-918 | |
| CPEs | cpe:2.3:a:jeecgboot:jeecgboot:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Jeecgboot
Jeecgboot jeecgboot |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-06-02T15:06:29.318Z
Reserved: 2026-05-31T09:56:40.755Z
Link: CVE-2026-10239
Updated: 2026-06-02T15:06:23.149Z
Status : Deferred
Published: 2026-06-01T09:16:15.670
Modified: 2026-06-01T15:15:37.293
Link: CVE-2026-10239
No data.
OpenCVE Enrichment
Updated: 2026-06-01T10:30:26Z