Vulnerability index

Browse CVEs

17 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Jpress MEDIUM 6.1
CVE-2024-12348

A vulnerability was found in Guizhou Xiaoma Technology jpress 5.1.2. It has been classified as problematic. Affected is the function AttachmentUtils.…

No fix yet
Fix from $1,600 2024-12-09
Jpress MEDIUM 5.4
CVE-2024-11971

A vulnerability classified as problematic was found in Guizhou Xiaoma Technology jpress 5.1.2. Affected by this vulnerability is an unknown functiona…

No fix yet
Fix from $1,600 2024-11-28
Jpress CRITICAL 9.8
CVE-2024-50919

Jpress until v5.1.1 has arbitrary file uploads on the windows platform, and the construction of non-standard file formats such as .jsp. can lead to a…

Fix: after 5.1.1
Fix from $2,300 2024-11-18
Jpress HIGH 7.5
CVE-2024-46468

A Server-Side Request Forgery (SSRF) vulnerability exists in the jpress <= v5.1.1, which can be exploited by an attacker to obtain sensitive informat…

Fix: after 5.1.1
Fix from $1,950 2024-10-11
Jpress HIGH 8.8
CVE-2024-43033

JPress through 5.1.1 on Windows has an arbitrary file upload vulnerability that could cause arbitrary code execution via ::$DATA to AttachmentControl…

Fix: after 5.1.1
Fix from $1,950 2024-08-22
Jpress HIGH 7.5
CVE-2024-32358

An issue in Jpress v.5.1.0 allows a remote attacker to execute arbitrary code via a crafted script to the custom plug-in module function, a different…

Mitigation only
Fix from $1,950 2024-04-25
Jpress HIGH 8.8
CVE-2022-23330

A remote code execution (RCE) vulnerability in HelloWorldAddonController.java of jpress v4.2.0 allows attackers to execute arbitrary code via a craft…

No fix yet
Fix from $1,950 2022-02-04
Jpress HIGH 8.8
CVE-2021-46114

jpress v 4.2.0 is vulnerable to RCE via io.jpress.module.product.ProductNotifyKit#doSendEmail. The admin panel provides a function through which atta…

Mitigation only
Fix from $1,950 2022-01-26
Jpress HIGH 7.2
CVE-2021-46115

jpress 4.2.0 is vulnerable to RCE via io.jpress.web.admin._TemplateController#doUploadFile. The admin panel provides a function through which attacke…

No fix yet
Fix from $1,950 2022-01-26
Jpress HIGH 7.2
CVE-2021-46116

jpress 4.2.0 is vulnerable to remote code execution via io.jpress.web.admin._TemplateController#doInstall. The admin panel provides a function throug…

No fix yet
Fix from $1,950 2022-01-26
Jpress HIGH 7.2
CVE-2021-46118

jpress 4.2.0 is vulnerable to remote code execution via io.jpress.module.article.kit.ArticleNotifyKit#doSendEmail. The admin panel provides a functio…

No fix yet
Fix from $1,950 2022-01-26
Jpress HIGH 7.2
CVE-2021-46117

jpress 4.2.0 is vulnerable to remote code execution via io.jpress.module.page.PageNotifyKit#doSendEmail. The admin panel provides a function through …

No fix yet
Fix from $1,950 2022-01-26
Jpress HIGH 8.8
CVE-2021-45808

jpress v4.2.0 allows users to register an account by default. With the account, user can upload arbitrary files to the server.

Mitigation only
Fix from $1,950 2022-01-19
Jpress CRITICAL 9.8
CVE-2021-45807

jpress v4.2.0 is vulnerable to command execution via io.jpress.web.admin._AddonController::doUploadAndInstall.

Mitigation only
Fix from $2,300 2022-01-13
Jpress HIGH 8.8
CVE-2021-45806

jpress v4.2.0 admin panel provides a function through which attackers can modify the template and inject some malicious code.

Mitigation only
Fix from $1,950 2022-01-13
Jpress MEDIUM 5.4
CVE-2021-33347

An issue was discovered in JPress v3.3.0 and below. There are XSS vulnerabilities in the template module and tag management module. If you log in to …

Fix: after 3.3.0
Fix from $1,600 2021-06-18
Jpress MEDIUM 5.4
CVE-2019-6278

XSS exists in JPress v1.0.4 via Markdown input, or Markdown input with the code input option.

No fix yet
Fix from $1,600 2019-01-14