Springblade
Bladex · 9 CVEs
Incorrect access control in the importUser function of SpringBlade v4.5.0 allows attackers with low-level privileges to…
Jan 26, 2026
Incorrect access control in the authRoutes function of SpringBlade v4.5.0 allows attackers with low-level privileges to…
Jan 23, 2026
chillzhuang SpringBlade list sql injection
Aug 20, 2024
An issue discovered in SpringBlade 3.7.1 allows attackers to obtain sensitive information via crafted GET request to ap…
Apr 30, 2024
An issue in SpringBlade v.3.7.0 and before allows a remote attacker to escalate privileges via the lack of permissions…
Jan 2, 2024
SpringBlade <=V3.6.0 is vulnerable to Incorrect Access Control due to incorrect configuration in the default gateway re…
Sep 18, 2023
In SpringBlade V3.6.0 when executing SQL query, the parameters submitted by the user are not wrapped in quotation marks…
Aug 29, 2023
SpringBlade v3.2.0 and below was discovered to contain a SQL injection vulnerability via the component customSqlSegment.
May 5, 2022
The DAO/DTO implementation in SpringBlade through 2.7.1 allows SQL Injection in an ORDER BY clause. This is related to…
Jul 30, 2020
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2025-70982 | Incorrect access control in the importUser function of SpringBlade v4.5.0 allows attackers with low-level privileges to arbitrarily import sensitive user data. | CRITICAL | 0.34% | Jan 26, 2026 |
| CVE-2025-70983 | Incorrect access control in the authRoutes function of SpringBlade v4.5.0 allows attackers with low-level privileges to escalate privileges. | CRITICAL | 0.41% | Jan 23, 2026 |
| CVE-2024-8023 | chillzhuang SpringBlade list sql injection | MEDIUM | 0.64% | Aug 20, 2024 |
| CVE-2024-33332 | An issue discovered in SpringBlade 3.7.1 allows attackers to obtain sensitive information via crafted GET request to api/blade-system/tenant. | HIGH | 0.68% | Apr 30, 2024 |
| CVE-2023-47458 | An issue in SpringBlade v.3.7.0 and before allows a remote attacker to escalate privileges via the lack of permissions control framework. | CRITICAL | 0.64% | Jan 2, 2024 |
| CVE-2023-40788 | SpringBlade <=V3.6.0 is vulnerable to Incorrect Access Control due to incorrect configuration in the default gateway resulting in unauthorized access to error… | MEDIUM | 0.77% | Sep 18, 2023 |
| CVE-2023-40787 | In SpringBlade V3.6.0 when executing SQL query, the parameters submitted by the user are not wrapped in quotation marks, which leads to SQL injection. | CRITICAL | 18.16% | Aug 29, 2023 |
| CVE-2022-27360 | SpringBlade v3.2.0 and below was discovered to contain a SQL injection vulnerability via the component customSqlSegment. | CRITICAL | 2.05% | May 5, 2022 |
| CVE-2020-16165 | The DAO/DTO implementation in SpringBlade through 2.7.1 allows SQL Injection in an ORDER BY clause. This is related to the /api/blade-log/api/list ascs and des… | CRITICAL | 1.21% | Jul 30, 2020 |
Showing 1 to 9 of 9 CVEs