← Back

Jfinal Cms

jfinal_cms

Vendor: Jflyfox • 51 CVEs

CVEs (51)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Jflyfox
1Jfinal Cms
Nov 21, 2024
Sep 9, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/site/list.
1Jflyfox
1Jfinal Cms
Nov 21, 2024
Sep 9, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/image/list.
1Jflyfox
1Jfinal Cms
Nov 21, 2024
Sep 9, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/imagealbum/list.
1Jflyfox
1Jfinal Cms
Nov 21, 2024
Sep 9, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/friendlylink/list.
1Jflyfox
1Jfinal Cms
Nov 21, 2024
Sep 9, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/folderrollpicture/list.
1Jflyfox
1Jfinal Cms
Nov 21, 2024
Sep 9, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/foldernotice/list.
1Jflyfox
1Jfinal Cms
Nov 21, 2024
Sep 9, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/contact/list.
1Jflyfox
1Jfinal Cms
Nov 21, 2024
Sep 9, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/comment/list.
1Jflyfox
1Jfinal Cms
Nov 21, 2024
Sep 9, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/article/list_approve.
1Jflyfox
1Jfinal Cms
Nov 21, 2024
Sep 9, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/article/list.
1Jflyfox
1Jfinal Cms
Nov 21, 2024
Aug 25, 2022
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Jfinal CMS v5.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the post title text field under the publish blog module.
1Jflyfox
1Jfinal Cms
Nov 21, 2024
Aug 23, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /jfinal_cms/system/role/list.
1Jflyfox
1Jfinal Cms
Nov 21, 2024
Aug 23, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /jfinal_cms/system/user/list.
1Jflyfox
1Jfinal Cms
Nov 21, 2024
Aug 3, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
JFinal CMS v5.1.0 was discovered to contain a SQL injection vulnerability via /system/user.
1Jflyfox
1Jfinal Cms
Nov 21, 2024
Jun 23, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Jfinal CMS v5.1.0 was discovered to contain a SQL injection vulnerability via the attrVal parameter at /jfinal_cms/system/dict/list.
1Jflyfox
1Jfinal Cms
Nov 21, 2024
Jun 23, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Jfinal CMS v5.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the keyword text field under the publish blog module.
1Jflyfox
1Jfinal Cms
Nov 21, 2024
Jun 2, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A cross-site scripting (XSS) vulnerability in Jfinal CMS v5.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted X-Forwarded-For request.
1Jflyfox
1Jfinal Cms
Nov 21, 2024
May 26, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Jfinal cms 5.1.0 is vulnerable to SQL Injection.
1Jflyfox
1Jfinal Cms
Nov 21, 2024
May 5, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A command execution vulnerability exists in jfinal_cms 5.0.1 via com.jflyfox.component.controller.Ueditor.
1Jflyfox
1Jfinal Cms
Nov 21, 2024
May 3, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Jfinal_cms 5.1.0 is vulnerable to SQL Injection via com.jflyfox.system.log.LogController.java.