PatchSiren

xianrendzw CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW xianrendzw CVE published 2026-08-19

CVE-2026-75979

The CVE-2026-75979 vulnerability affects EasyReport up to 2.0.17.0522_Beta, specifically in the DesignerController.java file's execSqlText/previewSqlText function, allowing for improper neutralization of special elements used in a template engine. This vulnerability has a low CVSS score of 2.1 and can be exploited remotely. Security teams and administrators responsible for EasyReport installations should [truncated]

MEDIUM xianrendzw CVE published 2026-05-26

CVE-2026-9524

A SQL injection vulnerability exists in xianrendzw EasyReport up to version 2.0.17.0522_Beta. The vulnerability resides in the `execute` function of a REST endpoint component, where improper sanitization of the `reportParams` argument allows remote attackers to inject malicious SQL commands. The vulnerability has a CVSS 4.0 base score of 5.3 (MEDIUM severity) with network attack vector, low attack complex [truncated]