VYPR

Jfinal

by Jfinal

Source repositories

CVEs (30)

  • CVE-2020-19146MedSep 15, 2021
    risk 0.42cvss 6.5epss 0.02

    Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information via the 'TemplatePath' parameter in the component 'jfinal_cms/admin/folder/list'.

  • CVE-2021-33348MedJun 24, 2021
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in JFinal framework v4.9.10 and below. The "set" method of the "Controller" class of jfinal framework is not strictly filtered, which will lead to XSS vulnerabilities in some cases.

  • CVE-2023-24747MedApr 5, 2023
    risk 0.35cvss 5.4epss 0.00

    Jfinal CMS v5.1 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /system/dict/list.

  • CVE-2020-19148MedSep 15, 2021
    risk 0.35cvss 5.4epss 0.01

    Cross Site Scripting (XSS) in Jfinal CMS v4.7.1 and earlier allows remote attackers to execute arbitrary code via the 'Nickname' parameter in the component '/jfinal_cms/front/person/profile.html'.

  • CVE-2024-57774MedJan 16, 2025
    risk 0.31cvss 4.8epss 0.00

    A cross-site scripting (XSS) vulnerability in the getBusinessUploadListPage?busid interface of JFinalOA before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

  • CVE-2024-57773MedJan 16, 2025
    risk 0.31cvss 4.8epss 0.00

    A cross-site scripting (XSS) vulnerability in the openSelectManyUserPage?orgid interface of JFinalOA before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

  • CVE-2024-57772MedJan 16, 2025
    risk 0.31cvss 4.8epss 0.00

    A cross-site scripting (XSS) vulnerability in the /bumph/getDraftListPage?type interface of JFinalOA before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

  • CVE-2024-57771MedJan 16, 2025
    risk 0.31cvss 4.8epss 0.00

    A cross-site scripting (XSS) vulnerability in the common/getEditPage?view interface of JFinalOA before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

  • CVE-2024-57776MedJan 16, 2025
    risk 0.30cvss 4.6epss 0.00

    A cross-site scripting (XSS) vulnerability in the /apply/getEditPage?view interface of JFinalOA before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

  • CVE-2025-3214MedApr 4, 2025
    risk 0.28cvss 4.3epss 0.00

    A vulnerability has been found in JFinal CMS up to 5.2.4 and classified as problematic. Affected by this vulnerability is the function engine.getTemplate of the file /readTemplate. The manipulation of the argument template leads to path traversal. The attack can be launched…

Page 2 of 2