CVE-2025-8963: Jeecg Jimureport
Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.
A vulnerability was determined in jeecgboot JimuReport up to 2.1.1. Affected by this issue is some unknown functionality of the file /drag/onlDragDataSource/testConnection of the component Data Large Screen Template. The manipulation leads to deserialization. The attack may be launched remotely. The vendor response to the GitHub issue report is: "Modified, next version updated".
Affected products
- Jeecg Jimureport: up to and including 2.1.1
Published 2025-08-14. Last modified 2026-06-17.