SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-67925

MEDIUM · CVSS 6.1 EPSS 0.26% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-17 · Last synced 2026-09-16

CyberRota Analysis

AI-Generated

JeecgBoot version 3.9.2 is vulnerable to a Cross Site Scripting (XSS) attack, which enables remote attackers to execute arbitrary code through the /airag/chat/upload endpoint. Organizations utilizing this version of JeecgBoot should prioritize remediation efforts to mitigate potential exploitation risks associated with this vulnerability.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-67925
Severity
MEDIUM
CVSS
6.1
EPSS
0.26%

Original NVD Description

Cross Site Scripting vulnerability in JeecgBoot v.3.9.2 allows a remote attacker to execute arbitrary code via the endpoint /airag/chat/upload