VYPR

Jspxcms

by Ujcms

CVEs (6)

  • CVE-2022-23329CriFeb 4, 2022
    risk 0.65cvss 9.8epss 0.14

    A vulnerability in ${"freemarker.template.utility.Execute"?new() of UJCMS Jspxcms v10.2.0 allows attackers to execute arbitrary commands via uploading malicious files.

  • CVE-2022-28090MedMay 4, 2022
    risk 0.42cvss 6.5epss 0.01

    Jspxcms v10.2.0 allows attackers to execute a Server-Side Request Forgery (SSRF) via /cmscp/ext/collect/fetch_url.do?url=.

  • CVE-2025-25772MedFeb 21, 2025
    risk 0.33cvss 5.1epss 0.00

    A Cross-Site Request Forgery (CSRF) in the component /back/UserController.java of Jspxcms v9.0 to v9.5 allows attackers to arbitrarily add Administrator accounts via a crafted request.

  • CVE-2024-1257LowFeb 6, 2024
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was found in Jspxcms 10.2.0. It has been classified as problematic. Affected is an unknown function of the file /ext/collect/find_text.do. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed…

  • CVE-2024-1256LowFeb 6, 2024
    risk 0.23cvss 3.5epss 0.01

    A vulnerability was found in Jspxcms 10.2.0 and classified as problematic. This issue affects some unknown processing of the file /ext/collect/filter_text.do. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to…

  • CVE-2024-0599LowJan 16, 2024
    risk 0.23cvss 3.5epss 0.01

    A vulnerability was found in Jspxcms 10.2.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file src\main\java\com\jspxcms\core\web\back\InfoController.java of the component Document Management Page. The manipulation of the…