Jfinal
Products
2- 30 CVEs
- 2 CVEs
Recent CVEs
31| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-57768 | Cri | 0.64 | 9.8 | 0.01 | Jan 16, 2025 | JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component validRoleKey?sysRole.key. | ||
| CVE-2024-53477 | Cri | 0.64 | 9.8 | 0.01 | Dec 2, 2024 | JFinal CMS 5.1.0 is vulnerable to Command Execution via unauthorized execution of deserialization in the file ApiForm.java | ||
| CVE-2021-31635 | Cri | 0.64 | 9.8 | 0.01 | Jun 26, 2023 | Server-Side Template Injection (SSTI) vulnerability in jFinal v.4.9.08 allows a remote attacker to execute arbitrary code via the template function. | ||
| CVE-2022-37203 | Cri | 0.64 | 9.8 | 0.01 | Sep 19, 2022 | JFinal CMS 5.1.0 is vulnerable to SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection. | ||
| CVE-2022-30500 | Cri | 0.64 | 9.8 | 0.01 | May 26, 2022 | Jfinal cms 5.1.0 is vulnerable to SQL Injection. | ||
| CVE-2021-31649 | Cri | 0.64 | 9.8 | 0.02 | Jun 24, 2021 | In applications using jfinal 4.9.08 and below, there is a deserialization vulnerability when using redis,may be vulnerable to remote code execute | ||
| CVE-2020-19155 | Hig | 0.58 | 8.8 | 0.08 | Sep 15, 2021 | Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information and/or execute arbitrary code via the 'FileManager.rename()' function in the component 'modules/filemanager/FileManagerController.java'. | ||
| CVE-2020-19151 | Hig | 0.58 | 8.8 | 0.05 | Sep 15, 2021 | Command Injection in Jfinal CMS v4.7.1 and earlier allows remote attackers to execute arbitrary code by uploading a malicious HTML template file via the component 'jfinal_cms/admin/filemanager/list'. | ||
| CVE-2024-57775 | Hig | 0.57 | 8.8 | 0.01 | Jan 16, 2025 | JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component getWorkFlowHis?insid. | ||
| CVE-2024-57770 | Hig | 0.57 | 8.8 | 0.01 | Jan 16, 2025 | JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component apply/save#oaContractApply.id. | ||
| CVE-2024-57769 | Hig | 0.57 | 8.8 | 0.01 | Jan 16, 2025 | JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component borrowmoney/listData?applyUser. | ||
| CVE-2022-37202 | Hig | 0.57 | 8.8 | 0.01 | Oct 26, 2022 | JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/advicefeedback/list | ||
| CVE-2022-37208 | Hig | 0.57 | 8.8 | 0.01 | Oct 13, 2022 | JFinal CMS 5.1.0 is vulnerable to SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection. | ||
| CVE-2022-37209 | Hig | 0.57 | 8.8 | 0.01 | Sep 27, 2022 | JFinal CMS 5.1.0 is affected by: SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection. | ||
| CVE-2022-37205 | Hig | 0.57 | 8.8 | 0.01 | Sep 20, 2022 | JFinal CMS 5.1.0 is affected by: SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection. | ||
| CVE-2022-37201 | Hig | 0.57 | 8.8 | 0.01 | Sep 15, 2022 | JFinal CMS 5.1.0 is vulnerable to SQL Injection. | ||
| CVE-2022-37207 | Hig | 0.57 | 8.8 | 0.01 | Sep 15, 2022 | JFinal CMS 5.1.0 is affected by: SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection | ||
| CVE-2020-19150 | Hig | 0.53 | 8.1 | 0.03 | Sep 15, 2021 | Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information or cause a denial of service via the 'FileManager.delete()' function in the component 'modules/filemanager/FileManagerController.java'. | ||
| CVE-2019-17352 | Hig | 0.49 | 7.5 | 0.02 | Oct 8, 2019 | In JFinal cos before 2019-08-13, as used in JFinal 4.4, there is a vulnerability that can bypass the isSafeFile() function: one can upload any type of file. For example, a .jsp file may be stored and almost immediately deleted, but this deletion step does not occur for certain… | ||
| CVE-2020-19154 | Med | 0.43 | 6.5 | 0.04 | Sep 15, 2021 | Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information via the 'FileManager.editFile()' function in the component 'modules/filemanager/FileManagerController.java'. |
- risk 0.64cvss 9.8epss 0.01
JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component validRoleKey?sysRole.key.
- risk 0.64cvss 9.8epss 0.01
JFinal CMS 5.1.0 is vulnerable to Command Execution via unauthorized execution of deserialization in the file ApiForm.java
- risk 0.64cvss 9.8epss 0.01
Server-Side Template Injection (SSTI) vulnerability in jFinal v.4.9.08 allows a remote attacker to execute arbitrary code via the template function.
- risk 0.64cvss 9.8epss 0.01
JFinal CMS 5.1.0 is vulnerable to SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection.
- risk 0.64cvss 9.8epss 0.01
Jfinal cms 5.1.0 is vulnerable to SQL Injection.
- risk 0.64cvss 9.8epss 0.02
In applications using jfinal 4.9.08 and below, there is a deserialization vulnerability when using redis,may be vulnerable to remote code execute
- risk 0.58cvss 8.8epss 0.08
Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information and/or execute arbitrary code via the 'FileManager.rename()' function in the component 'modules/filemanager/FileManagerController.java'.
- risk 0.58cvss 8.8epss 0.05
Command Injection in Jfinal CMS v4.7.1 and earlier allows remote attackers to execute arbitrary code by uploading a malicious HTML template file via the component 'jfinal_cms/admin/filemanager/list'.
- risk 0.57cvss 8.8epss 0.01
JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component getWorkFlowHis?insid.
- risk 0.57cvss 8.8epss 0.01
JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component apply/save#oaContractApply.id.
- risk 0.57cvss 8.8epss 0.01
JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component borrowmoney/listData?applyUser.
- risk 0.57cvss 8.8epss 0.01
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/advicefeedback/list
- risk 0.57cvss 8.8epss 0.01
JFinal CMS 5.1.0 is vulnerable to SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection.
- risk 0.57cvss 8.8epss 0.01
JFinal CMS 5.1.0 is affected by: SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection.
- risk 0.57cvss 8.8epss 0.01
JFinal CMS 5.1.0 is affected by: SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection.
- risk 0.57cvss 8.8epss 0.01
JFinal CMS 5.1.0 is vulnerable to SQL Injection.
- risk 0.57cvss 8.8epss 0.01
JFinal CMS 5.1.0 is affected by: SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection
- risk 0.53cvss 8.1epss 0.03
Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information or cause a denial of service via the 'FileManager.delete()' function in the component 'modules/filemanager/FileManagerController.java'.
- risk 0.49cvss 7.5epss 0.02
In JFinal cos before 2019-08-13, as used in JFinal 4.4, there is a vulnerability that can bypass the isSafeFile() function: one can upload any type of file. For example, a .jsp file may be stored and almost immediately deleted, but this deletion step does not occur for certain…
- risk 0.43cvss 6.5epss 0.04
Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information via the 'FileManager.editFile()' function in the component 'modules/filemanager/FileManagerController.java'.