VulnSea

X-SpringBoot vulnerabilities

CVEs whose affected-version data names the X-SpringBoot package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

4 CVEsRSS

CVE-2026-97064Critical· 9.1
today

X-SpringBoot through 6.0 ships with a hardcoded static master login verification code 172839 enabled by default in the database seed

X-SpringBoot through 6.0 ships with a hardcoded static master login verification code 172839 enabled by default in the database seed. Unauthenticated attackers can authenticate as any user by submitting the public master code to the emai…

▾ Midnightyzcheng90 · X-SpringBootvia NVD
CVE-2026-97060High· 7.2
today

X-SpringBoot through 6.0 lacks object-level authorization in user management endpoints, allowing sub-administrators to modify or delete users without ownership verification

X-SpringBoot through 6.0 lacks object-level authorization in user management endpoints, allowing sub-administrators to modify or delete users without ownership verification. Attackers with user-management permissions can reset passwords …

▾ Twilightyzcheng90 · X-SpringBootvia NVD
CVE-2026-100192Medium· 6.5
today

X-SpringBoot through 6.0 exposes appKey and appSecret credentials in the GET /application/manager/select endpoint without authentication or field filtering

X-SpringBoot through 6.0 exposes appKey and appSecret credentials in the GET /application/manager/select endpoint without authentication or field filtering. Unauthenticated attackers can retrieve these credentials and use them to send ar…

▾ Sunlityzcheng90 · X-SpringBootvia NVD
CVE-2026-97063Critical· 9.1PoC
today

X-SpringBoot through 6.0 returns login verification codes in HTTP responses from unauthenticated endpoints GET /sys/mobile/code and GET /sys/email/code without sending them to account owners

X-SpringBoot through 6.0 returns login verification codes in HTTP responses from unauthenticated endpoints GET /sys/mobile/code and GET /sys/email/code without sending them to account owners. Attackers can request codes using known mobil…

▾ Abyssalyzcheng90 · X-SpringBootvia NVD
X-SpringBoot vulnerabilities (CVEs) · VulnSea