Known Vulnerabilities for Jsherp by Jishenghua
Listed below are 10 of the newest known vulnerabilities associated with "Jsherp" by "Jishenghua".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-94501 json | jshERP through 3.6 contains an authorization bypass vulnerability in the userBusiness CRUD endpoints that allows authenticate... | Not Provided | 2026-09-21 | 2026-09-21 |
| CVE-2026-94497 json | jshERP through 3.6 fails to validate object ownership in by-id info, update, and delete endpoints across multiple resource ty... | Not Provided | 2026-09-21 | 2026-09-22 |
| CVE-2026-94496 json | jshERP through 3.6 fails to validate caller permissions in role management endpoints, allowing authenticated users to modify ... | Not Provided | 2026-09-21 | 2026-09-21 |
| CVE-2026-94495 json | jshERP through 3.6 fails to properly validate user privileges in SystemConfigService.updateSystemConfig, allowing authenticat... | Not Provided | 2026-09-21 | 2026-09-21 |
| CVE-2026-94494 json | jshERP through 3.6 contains a tenant isolation bypass vulnerability that allows authenticated users to read other tenants' re... | Not Provided | 2026-09-21 | 2026-09-21 |
| CVE-2026-94414 json | jshERP through 3.6 is missing an authorization check on the POST /userBusiness/updateBtnStr endpoint that allows authenticate... | Not Provided | 2026-09-21 | 2026-09-21 |
| CVE-2026-94413 json | jshERP through 3.6 fails to redact password hashes in the /user/info endpoint, allowing authenticated users to retrieve unsal... | Not Provided | 2026-09-21 | 2026-09-22 |
| CVE-2026-94412 json | jshERP through 3.6 contains an authorization bypass vulnerability in the POST /user/resetPwd endpoint that allows authenticat... | Not Provided | 2026-09-21 | 2026-09-21 |
| CVE-2026-94411 json | jshERP 3.6 contains a privilege escalation vulnerability in the updateOneValueByKeyIdAndType endpoint that allows authenticat... | Not Provided | 2026-09-21 | 2026-09-21 |
| CVE-2026-1588 json | Not Provided | 2026-01-29 | 2026-04-29 |