Jfinal
Products
2- 30 CVEs
- 16 CVEs
Recent CVEs
40| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-57768 | Cri | 0.64 | 9.8 | 0.01 | Jan 16, 2025 | JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component validRoleKey?sysRole.key. | ||
| CVE-2024-53477 | Cri | 0.64 | 9.8 | 0.01 | Dec 2, 2024 | JFinal CMS 5.1.0 is vulnerable to Command Execution via unauthorized execution of deserialization in the file ApiForm.java | ||
| CVE-2021-31635 | Cri | 0.64 | 9.8 | 0.01 | Jun 26, 2023 | Server-Side Template Injection (SSTI) vulnerability in jFinal v.4.9.08 allows a remote attacker to execute arbitrary code via the template function. | ||
| CVE-2023-30349 | Cri | 0.64 | 9.8 | 0.02 | Apr 27, 2023 | JFinal CMS v5.1.0 was discovered to contain a remote code execution (RCE) vulnerability via the ActionEnter function. | ||
| CVE-2022-37203 | Cri | 0.64 | 9.8 | 0.02 | Sep 19, 2022 | JFinal CMS 5.1.0 is vulnerable to SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection. | ||
| CVE-2022-30500 | Cri | 0.64 | 9.8 | 0.01 | May 26, 2022 | Jfinal cms 5.1.0 is vulnerable to SQL Injection. | ||
| CVE-2021-31649 | Cri | 0.64 | 9.8 | 0.02 | Jun 24, 2021 | In applications using jfinal 4.9.08 and below, there is a deserialization vulnerability when using redis,may be vulnerable to remote code execute | ||
| CVE-2020-19155 | Hig | 0.58 | 8.8 | 0.08 | Sep 15, 2021 | Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information and/or execute arbitrary code via the 'FileManager.rename()' function in the component 'modules/filemanager/FileManagerController.java'. | ||
| CVE-2020-19151 | Hig | 0.58 | 8.8 | 0.05 | Sep 15, 2021 | Command Injection in Jfinal CMS v4.7.1 and earlier allows remote attackers to execute arbitrary code by uploading a malicious HTML template file via the component 'jfinal_cms/admin/filemanager/list'. | ||
| CVE-2024-57775 | Hig | 0.57 | 8.8 | 0.01 | Jan 16, 2025 | JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component getWorkFlowHis?insid. | ||
| CVE-2024-57770 | Hig | 0.57 | 8.8 | 0.01 | Jan 16, 2025 | JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component apply/save#oaContractApply.id. | ||
| CVE-2024-57769 | Hig | 0.57 | 8.8 | 0.01 | Jan 16, 2025 | JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component borrowmoney/listData?applyUser. | ||
| CVE-2022-37202 | Hig | 0.57 | 8.8 | 0.01 | Oct 26, 2022 | JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/advicefeedback/list | ||
| CVE-2022-37208 | Hig | 0.57 | 8.8 | 0.01 | Oct 13, 2022 | JFinal CMS 5.1.0 is vulnerable to SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection. | ||
| CVE-2022-37209 | Hig | 0.57 | 8.8 | 0.02 | Sep 27, 2022 | JFinal CMS 5.1.0 is affected by: SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection. | ||
| CVE-2022-37205 | Hig | 0.57 | 8.8 | 0.02 | Sep 20, 2022 | JFinal CMS 5.1.0 is affected by: SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection. | ||
| CVE-2022-37201 | Hig | 0.57 | 8.8 | 0.02 | Sep 15, 2022 | JFinal CMS 5.1.0 is vulnerable to SQL Injection. | ||
| CVE-2022-37207 | Hig | 0.57 | 8.8 | 0.02 | Sep 15, 2022 | JFinal CMS 5.1.0 is affected by: SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection | ||
| CVE-2022-34928 | Hig | 0.57 | 8.8 | 0.01 | Aug 3, 2022 | JFinal CMS v5.1.0 was discovered to contain a SQL injection vulnerability via /system/user. | ||
| CVE-2020-19150 | Hig | 0.53 | 8.1 | 0.03 | Sep 15, 2021 | Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information or cause a denial of service via the 'FileManager.delete()' function in the component 'modules/filemanager/FileManagerController.java'. |
- risk 0.64cvss 9.8epss 0.01
JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component validRoleKey?sysRole.key.
- risk 0.64cvss 9.8epss 0.01
JFinal CMS 5.1.0 is vulnerable to Command Execution via unauthorized execution of deserialization in the file ApiForm.java
- risk 0.64cvss 9.8epss 0.01
Server-Side Template Injection (SSTI) vulnerability in jFinal v.4.9.08 allows a remote attacker to execute arbitrary code via the template function.
- risk 0.64cvss 9.8epss 0.02
JFinal CMS v5.1.0 was discovered to contain a remote code execution (RCE) vulnerability via the ActionEnter function.
- risk 0.64cvss 9.8epss 0.02
JFinal CMS 5.1.0 is vulnerable to SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection.
- risk 0.64cvss 9.8epss 0.01
Jfinal cms 5.1.0 is vulnerable to SQL Injection.
- risk 0.64cvss 9.8epss 0.02
In applications using jfinal 4.9.08 and below, there is a deserialization vulnerability when using redis,may be vulnerable to remote code execute
- risk 0.58cvss 8.8epss 0.08
Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information and/or execute arbitrary code via the 'FileManager.rename()' function in the component 'modules/filemanager/FileManagerController.java'.
- risk 0.58cvss 8.8epss 0.05
Command Injection in Jfinal CMS v4.7.1 and earlier allows remote attackers to execute arbitrary code by uploading a malicious HTML template file via the component 'jfinal_cms/admin/filemanager/list'.
- risk 0.57cvss 8.8epss 0.01
JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component getWorkFlowHis?insid.
- risk 0.57cvss 8.8epss 0.01
JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component apply/save#oaContractApply.id.
- risk 0.57cvss 8.8epss 0.01
JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component borrowmoney/listData?applyUser.
- risk 0.57cvss 8.8epss 0.01
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/advicefeedback/list
- risk 0.57cvss 8.8epss 0.01
JFinal CMS 5.1.0 is vulnerable to SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection.
- risk 0.57cvss 8.8epss 0.02
JFinal CMS 5.1.0 is affected by: SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection.
- risk 0.57cvss 8.8epss 0.02
JFinal CMS 5.1.0 is affected by: SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection.
- risk 0.57cvss 8.8epss 0.02
JFinal CMS 5.1.0 is vulnerable to SQL Injection.
- risk 0.57cvss 8.8epss 0.02
JFinal CMS 5.1.0 is affected by: SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection
- risk 0.57cvss 8.8epss 0.01
JFinal CMS v5.1.0 was discovered to contain a SQL injection vulnerability via /system/user.
- risk 0.53cvss 8.1epss 0.03
Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information or cause a denial of service via the 'FileManager.delete()' function in the component 'modules/filemanager/FileManagerController.java'.