Current issue state, recent activity, and per-issue timelines from the indexed issue data.
| Date | Opened | Closed | Comments | Events | Open Backlog |
|---|---|---|---|---|---|
| 2026-09-08 | 0 | 0 | 0 | 0 | 0 |
| 2026-09-07 | 0 | 0 | 0 | 0 | 0 |
| 2026-09-06 | 0 | 0 | 0 | 0 | 0 |
| 2026-09-05 | 0 | 0 | 0 | 0 | 0 |
| 2026-09-04 | 0 | 0 | 0 | 0 | 0 |
| 2026-09-03 | 0 | 0 | 0 | 0 | 0 |
| 2026-09-02 | 0 | 0 | 0 | 0 | 18 |
| 2026-09-01 | 1 | 0 | 0 | 0 | 0 |
| 2026-08-31 | 0 | 0 | 0 | 0 | 0 |
| 2026-08-30 | 0 | 0 | 0 | 0 | 0 |
| 2026-08-29 | 0 | 0 | 0 | 0 | 0 |
| 2026-08-28 | 0 | 0 | 0 | 0 | 0 |
| 2026-08-27 | 0 | 0 | 0 | 0 | 0 |
| 2026-08-26 | 0 | 0 | 0 | 0 | 0 |
Opened: 0
Closed: 0
Comments: 0
Events: 0
No label distribution is available yet.
| Issue | Author | State | Labels | Comments | Reactions | Updated |
|---|---|---|---|---|---|---|
#913 Courtesy notice for an independent Java 21 and Spring Boot 4.1.1 port Opened 7 days ago | SovNodeAI | open | No labels | 0 | 0 | 7 days ago |
#912 [Security] JWT userId 未与 Redis 在线会话绑定,导致跨用户身份混淆与条件性垂直越权 Opened 1 month ago | 28Hus | open | No labels | 3 | 0 | 8 days ago |
#903 [Security] Missing authorization on Tools (Email / Alipay) and Code-Generator controllers enables vertical privilege escalation Opened 3 months ago | geo-chen | open | No labels | 1 | 0 | 2 months ago |
#910 [Security] Broken Access Control - UserController Opened 2 months ago | StephenClash | open | No labels | 0 | 0 | 2 months ago |
#909 [Security] Broken Access Control - LocalStorageController Opened 2 months ago | StephenClash | open | No labels | 0 | 0 | 2 months ago |
#906 [Security] OS command injection in deploy server-reduction (`appName`) Opened 2 months ago | Ku4D3 | open | No labels | 0 | 0 | 2 months ago |
#907 [Security] SSRF via attacker-controlled JDBC URL in database maintenance endpoints Opened 2 months ago | Ku4D3 | open | No labels | 0 | 0 | 2 months ago |
#908 [Security] Arbitrary file write via code-generator `tableName` (path traversal) Opened 2 months ago | Ku4D3 | open | No labels | 0 | 0 | 2 months ago |
#868 The version of the MySQL connector used by eladmin v2.6 is outdated, which makes it vulnerable to JDBC deserialization attacks. Opened 2 years ago | ghost | open | No labels | 1 | 0 | 3 months ago |
#901 [Security]Directory Traversal in File Upload Path Construction Allows Write Outside the Intended Upload Directory Opened 4 months ago | v9d0g | open | No labels | 1 | 0 | 3 months ago |
#904 Arbitrary file read via /api/database/testConnect: the sanitizeJdbcUrl blocklist is bypassable Opened 3 months ago | MarkLee131 | open | No labels | 1 | 0 | 3 months ago |
#902 [Security]Users with low privileges can reset the password of any user. Opened 4 months ago | v9d0g | open | No labels | 0 | 0 | 4 months ago |
#900 [Security] Server-Side Request Forgery (SSRF) via Insecure JDBC Connection Testing Opened 4 months ago | AnalogyC0de | open | No labels | 0 | 0 | 4 months ago |
#899 [Secruity] Command Injection via SSH Script Injection in App Management in elunez_eladmin Opened 4 months ago | AnalogyC0de | open | No labels | 0 | 0 | 4 months ago |
#898 PUT /api/roles 权限检查绕过 Opened 5 months ago | AliceS614 | closed - completed | No labels | 0 | 0 | 4 months ago |
#897 isAdmin标志导致垂直越权 Opened 5 months ago | AliceS614 | closed - completed | No labels | 0 | 0 | 4 months ago |
#891 数据库连接串不起作用 Opened 5 months ago | v9d0g | closed - completed | No labels | 2 | 0 | 4 months ago |
#892 建议修改tableName传参方式 Opened 5 months ago | v9d0g | open | No labels | 0 | 0 | 5 months ago |
#886 CSV/XLSX Injection in 19 Endpoints of eladmin ≤ 2.7 (CWE-1236) Opened 1 year ago | ez-lbz | closed - completed | No labels | 0 | 0 | 6 months ago |
#888 Authenticated cmdi: startServer execute request-body scripts on deployed servers Opened 7 months ago | mukyuuhate | open | No labels | 0 | 0 | 7 months ago |
#885 Sensitive Information Disclosure via /auth/info in eladmin ≤ 2.7(CWE-200) Opened 1 year ago | ez-lbz | open | No labels | 1 | 0 | 1 year ago |
#883 Druid credentials hardcoded vulnerability Opened 1 year ago | NinjaGPT | closed - completed | No labels | 4 | 0 | 1 year ago |
#884 Hardcoded DES Key Vulnerability in eladmin ≤ 2.7(CWE-321) Opened 1 year ago | ez-lbz | open | No labels | 0 | 0 | 1 year ago |
#870 [线程安全] TokenProvider类中复用 JwtBuilder 实例导致并发环境下 Token 生成错误 Opened 2 years ago | zxm82081372 | closed - completed | No labels | 0 | 0 | 1 year ago |
#873 There is a command execution vulnerability in version 2.7 Opened 1 year ago | hacker-wp | closed - completed | No labels | 1 | 0 | 1 year ago |