Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
5.3

UEditor in JEEWMS 3.7 can lead to Cross-Site Scripting attacks

CVE-2026-3027
Summary

A security flaw in the UEditor component of JEEWMS 3.7 makes it possible for hackers to inject malicious code onto a website. This can happen when a user interacts with a crafted URL or link. To protect your site, update to the latest version of JEEWMS or apply a patch if available.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versionsFix available
jeewms jeewms > 3.2 , <= 3.7 –
Original title
A vulnerability was found in erzhongxmu JEEWMS up to 3.7. This affects an unknown part of the file src/main/webapp/plug-in/ueditor/jsp/getContent.jsp of the component UEditor. The manipulation of t...
Original description
A vulnerability was found in erzhongxmu JEEWMS up to 3.7. This affects an unknown part of the file src/main/webapp/plug-in/ueditor/jsp/getContent.jsp of the component UEditor. The manipulation of the argument myEditor results in cross site scripting. The attack can be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
nvd CVSS2.0 5.0
nvd CVSS3.1 6.1
nvd CVSS4.0 5.3
Vulnerability type
CWE-79 Cross-site Scripting (XSS)
CWE-94 Code Injection
Published: 23 Feb 2026 · Updated: 12 Mar 2026 · First seen: 6 Mar 2026