Vulnerability index

Browse CVEs

51 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2022-36527 Jfinal CMS v5.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the post title text field under the p… Jfinal Cms No fix yet Fix from $1,6002022-08-25 CRITICAL 9.8 CVE-2022-37223 JFinal CMS 5.1.0 is vulnerable to SQL Injection via /jfinal_cms/system/role/list. Jfinal Cms No fix yet Fix from $2,3002022-08-23 CRITICAL 9.8 CVE-2022-37199 JFinal CMS 5.1.0 is vulnerable to SQL Injection via /jfinal_cms/system/user/list. Jfinal Cms No fix yet Fix from $2,3002022-08-23 HIGH 8.8 CVE-2022-34928 JFinal CMS v5.1.0 was discovered to contain a SQL injection vulnerability via /system/user. Jfinal Cms No fix yet Fix from $1,9502022-08-03 HIGH 7.2 CVE-2022-33114 Jfinal CMS v5.1.0 was discovered to contain a SQL injection vulnerability via the attrVal parameter at /jfinal_cms/system/dict/list. Jfinal Cms No fix yet Fix from $1,9502022-06-23 MEDIUM 5.4 CVE-2022-33113 Jfinal CMS v5.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the keyword text field under the publ… Jfinal Cms No fix yet Fix from $1,6002022-06-23 MEDIUM 5.4 CVE-2022-29648 A cross-site scripting (XSS) vulnerability in Jfinal CMS v5.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted X-Forwarded-F… Jfinal Cms No fix yet Fix from $1,6002022-06-02 CRITICAL 9.8 CVE-2022-30500 Jfinal cms 5.1.0 is vulnerable to SQL Injection. Jfinal Cms No fix yet Fix from $2,3002022-05-26 CRITICAL 9.8 CVE-2021-42242 A command execution vulnerability exists in jfinal_cms 5.0.1 via com.jflyfox.component.controller.Ueditor. Jfinal Cms No fix yet Fix from $2,3002022-05-05 HIGH 7.2 CVE-2022-28505 Jfinal_cms 5.1.0 is vulnerable to SQL Injection via com.jflyfox.system.log.LogController.java. Jfinal Cms No fix yet Fix from $1,9502022-05-03 MEDIUM 5.4 CVE-2022-27111 Jfinal_CMS 5.1.0 allows attackers to use the feedback function to send malicious XSS code to the administrator backend and execute it. Jfinal Cms No fix yet Fix from $1,6002022-04-11 MEDIUM 5.4 CVE-2021-46087 In jfinal_cms >= 5.1 0, there is a storage XSS vulnerability in the background system of CMS. Because developers do not filter the parameters submitt… Jfinal Cms No fix yet Fix from $1,6002022-01-25 HIGH 7.5 CVE-2021-37262 JFinal_cms 5.1.0 is vulnerable to regex injection that may lead to Denial of Service. Jfinal Cms Patch available Fix from $1,9502021-12-16 HIGH 7.5 CVE-2021-40639 Improper access control in Jfinal CMS 5.1.0 allows attackers to access sensitive information via /classes/conf/db.properties&config=filemanager.confi… Jfinal Cms No fix yet Fix from $1,9502021-09-15 HIGH 8.8 CVE-2020-19151EPSS 5% Command Injection in Jfinal CMS v4.7.1 and earlier allows remote attackers to execute arbitrary code by uploading a malicious HTML template file via … Jfinal Cms after 4.7.1 Fix from $1,9502021-09-15 HIGH 8.8 CVE-2020-19155EPSS 8% Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information and/or execute arbitrary code via th… Jfinal Cms after 4.7.1 Fix from $1,9502021-09-15 HIGH 8.1 CVE-2020-19150 Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information or cause a denial of service via the… Jfinal Cms after 4.7.1 Fix from $1,9502021-09-15 MEDIUM 6.5 CVE-2020-19154 Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information via the 'FileManager.editFile()' fun… Jfinal Cms after 4.7.1 Fix from $1,6002021-09-15 MEDIUM 5.4 CVE-2020-19148 Cross Site Scripting (XSS) in Jfinal CMS v4.7.1 and earlier allows remote attackers to execute arbitrary code via the 'Nickname' parameter in the com… Jfinal Cms after 4.7.1 Fix from $1,6002021-09-15 MEDIUM 6.5 CVE-2020-19146 Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information via the 'TemplatePath' parameter in … Jfinal Cms after 4.7.1 Fix from $1,6002021-09-15 MEDIUM 6.5 CVE-2020-19147 Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive infromation via the 'getFolder()' function in th… Jfinal Cms after 4.7.1 Fix from $1,6002021-09-15