VYPR

JFinalcms

by JFinalcms

CVEs (49)

  • CVE-2023-49487MedDec 8, 2023
    risk 0.35cvss 5.4epss 0.00

    JFinalCMS v5.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the navigation management department.

  • CVE-2023-49486MedDec 8, 2023
    risk 0.35cvss 5.4epss 0.00

    JFinalCMS v5.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the model management department.

  • CVE-2023-49485MedDec 8, 2023
    risk 0.35cvss 5.4epss 0.00

    JFinalCMS v5.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the column management department.

  • CVE-2023-41599MedSep 19, 2023
    risk 0.35cvss 5.3epss 0.12

    An issue in the component /common/DownController.java of JFinalCMS v5.0.0 allows attackers to execute a directory traversal.

  • CVE-2024-12349MedDec 9, 2024
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was found in JFinalCMS 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/tag/save. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has…

  • CVE-2024-8706MedSep 12, 2024
    risk 0.28cvss 4.3epss 0.01

    A vulnerability was found in JFinalCMS up to 20240903. It has been classified as problematic. This affects the function update of the file /admin/template/update of the component com.cms.util.TemplateUtils. The manipulation of the argument fileName leads to path traversal. It is…

  • CVE-2024-8694LowSep 11, 2024
    risk 0.25cvss 3.8epss 0.01

    A vulnerability, which was classified as problematic, was found in JFinalCMS up to 20240903. This affects the function update of the file /admin/template/update of the component com.cms.controller.admin.TemplateController. The manipulation of the argument fileName leads to path…

  • CVE-2024-5379LowMay 26, 2024
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was found in JFinalCMS up to 20240111. It has been rated as problematic. This issue affects some unknown processing of the file /admin/template. The manipulation of the argument directory leads to cross site scripting. The attack may be initiated remotely. The…

  • CVE-2024-5310LowMay 24, 2024
    risk 0.16cvss 2.4epss 0.00

    A vulnerability classified as problematic has been found in JFinalCMS up to 20221020. This affects an unknown part of the file /admin/content. The manipulation of the argument Title leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has…

Page 3 of 3