Gitee Exploits

415 exploits tracked across all sources.

Sort: Activity Stars
CVE-2025-7935 GITEE MEDIUM java
Fuyang Lipengjun Platform < 2025-06-29 - Injection
A vulnerability, which was classified as critical, was found in fuyang_lipengjun platform up to ca9aceff6902feb7b0b6bf510842aea88430796a. Affected is the function SysLogController of the file platform-admin/src/main/java/com/platform/controller/SysLogController.java. The manipulation of the argument key leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available.
by fuyang_lipengjun
27,648 stars
CVSS 6.3
CVE-2025-7936 GITEE MEDIUM java
Fuyang Lipengjun Platform - Injection
A vulnerability has been found in fuyang_lipengjun platform up to ca9aceff6902feb7b0b6bf510842aea88430796a and classified as critical. Affected by this vulnerability is the function queryPage of the file com/platform/controller/ScheduleJobLogController.java. The manipulation of the argument beanName/methodName leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available.
by fuyang_lipengjun
27,648 stars
CVSS 6.3
CVE-2025-7552 GITEE MEDIUM java
Dromara Northstar <7.3.5 - Improper Access Controls
A vulnerability was found in Dromara Northstar up to 7.3.5. It has been rated as critical. Affected by this issue is the function preHandle of the file northstar-main/src/main/java/org/dromara/northstar/web/interceptor/AuthorizationInterceptor.java of the component Path Handler. The manipulation of the argument Request leads to improper access controls. The attack may be launched remotely. Upgrading to version 7.3.6 is able to address this issue. The patch is identified as 8d521bbf531de59b09b8629a9cbf667870ad2541. It is recommended to upgrade the affected component.
by yu199195
4,265 stars
CVSS 6.3
CVE-2025-7552 GITEE MEDIUM java
Dromara Northstar <7.3.5 - Improper Access Controls
A vulnerability was found in Dromara Northstar up to 7.3.5. It has been rated as critical. Affected by this issue is the function preHandle of the file northstar-main/src/main/java/org/dromara/northstar/web/interceptor/AuthorizationInterceptor.java of the component Path Handler. The manipulation of the argument Request leads to improper access controls. The attack may be launched remotely. Upgrading to version 7.3.6 is able to address this issue. The patch is identified as 8d521bbf531de59b09b8629a9cbf667870ad2541. It is recommended to upgrade the affected component.
by yu199195
4,265 stars
CVSS 6.3
CVE-2025-8927 GITEE LOW java
mtons mblog <3.5.0 - Auth Bypass
A vulnerability was determined in mtons mblog up to 3.5.0. Affected by this issue is some unknown functionality of the file /email/send_code of the component Verification Code Handler. The manipulation of the argument email leads to improper restriction of excessive authentication attempts. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used.
by mtons
3,324 stars
CVSS 3.7
CVE-2025-8992 GITEE MEDIUM java
Mtons Mblog < 3.5.0 - Missing Authorization
A vulnerability has been found in mtons mblog up to 3.5.0. Affected by this issue is some unknown functionality. The manipulation leads to cross-site request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
by mtons
3,324 stars
CVSS 4.3
CVE-2025-9004 GITEE LOW java
mtons mblog <3.5.0 - Auth Bypass
A vulnerability was found in mtons mblog up to 3.5.0. This issue affects some unknown processing of the file /settings/password. The manipulation leads to improper restriction of excessive authentication attempts. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used.
by mtons
3,324 stars
CVSS 3.7
CVE-2025-9005 GITEE LOW java
Mtons Mblog < 3.5.0 - Information Disclosure
A vulnerability was determined in mtons mblog up to 3.5.0. Affected is an unknown function of the file /register. The manipulation leads to information exposure through error message. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used.
by mtons
3,324 stars
CVSS 3.7
CVE-2025-9407 GITEE LOW java
mtons mblog <3.5.0 - XSS
A flaw has been found in mtons mblog up to 3.5.0. Affected by this vulnerability is an unknown functionality of the file /settings/profile. Executing manipulation of the argument signature can lead to cross site scripting. The attack may be launched remotely. The exploit has been published and may be used. Other parameters might be affected as well.
by mtons
3,324 stars
CVSS 3.5
CVE-2025-9429 GITEE LOW java
mtons mblog <3.5.0 - XSS
A security vulnerability has been detected in mtons mblog up to 3.5.0. This vulnerability affects unknown code of the file /post/submit of the component Post Handler. The manipulation of the argument content/title/ leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used.
by mtons
3,324 stars
CVSS 3.5
CVE-2025-9429 GITEE LOW java
mtons mblog <3.5.0 - XSS
A security vulnerability has been detected in mtons mblog up to 3.5.0. This vulnerability affects unknown code of the file /post/submit of the component Post Handler. The manipulation of the argument content/title/ leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used.
by mtons
3,324 stars
CVSS 3.5
CVE-2025-9430 GITEE LOW java
mtons mblog <3.5.0 - XSS
A vulnerability was detected in mtons mblog up to 3.5.0. This issue affects some unknown processing of the file /admin/options/update. The manipulation of the argument input results in cross site scripting. It is possible to launch the attack remotely. The exploit is now public and may be used.
by mtons
3,324 stars
CVSS 2.4
CVE-2025-9431 GITEE MEDIUM java
mtons mblog <3.5.0 - XSS
A flaw has been found in mtons mblog up to 3.5.0. Impacted is an unknown function of the file /search. This manipulation of the argument kw causes cross site scripting. The attack can be initiated remotely. The exploit has been published and may be used.
by mtons
3,324 stars
CVSS 4.3
CVE-2025-9432 GITEE MEDIUM java
mtons mblog <3.5.0 - XSS
A vulnerability has been found in mtons mblog up to 3.5.0. The affected element is an unknown function of the file /admin/post/list of the component Admin Panel. Such manipulation of the argument Title leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
by mtons
3,324 stars
CVSS 4.3
CVE-2025-9433 GITEE MEDIUM java
mtons mblog <3.5.0 - XSS
A vulnerability was found in mtons mblog up to 3.5.0. The impacted element is an unknown function of the file /admin/user/list of the component Admin Panel. Performing manipulation of the argument Name results in cross site scripting. The attack may be initiated remotely. The exploit has been made public and could be used.
by mtons
3,324 stars
CVSS 4.3
CVE-2025-9647 GITEE MEDIUM java
mtons mblog <3.5.0 - XSS
A weakness has been identified in mtons mblog up to 3.5.0. This issue affects some unknown processing of the file /admin/role/list. This manipulation of the argument Name causes cross site scripting. The attack may be initiated remotely. The exploit has been made available to the public and could be exploited.
by mtons
3,324 stars
CVSS 4.3
CVE-2025-8752 GITEE HIGH java
Xuanshao Spring-shiro-training - Command Injection
A vulnerability was found in wangzhixuan spring-shiro-training up to 94812c1fd8f7fe796c931f4984ff1aa0671ab562. It has been declared as critical. This vulnerability affects unknown code of the file /role/add. The manipulation leads to command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available.
by wangzhixuan
2,385 stars
CVSS 7.3
CVE-2025-8815 GITEE HIGH java
Morning - Path Traversal
A vulnerability was found in 猫宁i Morning up to bc782730c74ff080494f145cc363a0b4f43f7d3e. It has been classified as critical. Affected is an unknown function of the file /index of the component Shiro Configuration. The manipulation leads to path traversal. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available.
by morning-pro
2,312 stars
CVSS 7.3
CVE-2025-8123 GITEE MEDIUM java
Deerwms Deer-wms-2 < 3.3 - Injection
A vulnerability was found in deerwms deer-wms-2 up to 3.3. It has been classified as critical. Affected is an unknown function of the file /system/dept/edit. The manipulation of the argument ancestors leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
by deerwms
1,418 stars
CVSS 6.3
CVE-2025-8124 GITEE MEDIUM java
Deerwms Deer-wms-2 < 3.3 - Injection
A vulnerability was found in deerwms deer-wms-2 up to 3.3. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /system/role/authUser/unallocatedList. The manipulation of the argument params[dataScope] leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
by deerwms
1,418 stars
CVSS 6.3
CVE-2025-8125 GITEE MEDIUM java
Deerwms Deer-wms-2 < 3.3 - Injection
A vulnerability was found in deerwms deer-wms-2 up to 3.3. It has been rated as critical. Affected by this issue is some unknown functionality of the file /system/role/authUser/allocatedList. The manipulation of the argument params[dataScope] leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
by deerwms
1,418 stars
CVSS 6.3
CVE-2025-8126 GITEE MEDIUM java
Deerwms Deer-wms-2 < 3.3 - Injection
A vulnerability classified as critical has been found in deerwms deer-wms-2 up to 3.3. This affects an unknown part of the file /system/user/export. The manipulation of the argument params[dataScope] leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
by deerwms
1,418 stars
CVSS 6.3
CVE-2025-8127 GITEE MEDIUM java
Deerwms Deer-wms-2 < 3.3 - Injection
A vulnerability classified as critical was found in deerwms deer-wms-2 up to 3.3. This vulnerability affects unknown code of the file /system/user/list. The manipulation of the argument params[dataScope] leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
by deerwms
1,418 stars
CVSS 6.3
CVE-2025-8161 GITEE MEDIUM java
Deerwms Deer-wms-2 < 3.3 - Injection
A vulnerability classified as critical was found in deerwms deer-wms-2 up to 3.3. Affected by this vulnerability is an unknown functionality of the file /system/role/export. The manipulation of the argument params[dataScope] leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
by deerwms
1,418 stars
CVSS 6.3
CVE-2025-8162 GITEE MEDIUM java
Deerwms Deer-wms-2 < 3.3 - Injection
A vulnerability, which was classified as critical, has been found in deerwms deer-wms-2 up to 3.3. Affected by this issue is some unknown functionality of the file /system/dept/list. The manipulation of the argument params[dataScope] leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
by deerwms
1,418 stars
CVSS 6.3