VYPR
Vendor

Jflyfox

Products
1
CVEs
52
Across products
52
Status
Private

Products

1

Recent CVEs

52
View all 52 CVEs →
  • CVE-2024-53477CriDec 2, 2024
    risk 0.64cvss 9.8epss 0.01

    JFinal CMS 5.1.0 is vulnerable to Command Execution via unauthorized execution of deserialization in the file ApiForm.java

  • CVE-2023-47503CriNov 28, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue in jflyfox jfinalCMS v.5.1.0 allows a remote attacker to execute arbitrary code via a crafted script to the login.jsp component in the template management module.

  • CVE-2023-30349CriApr 27, 2023
    risk 0.64cvss 9.8epss 0.02

    JFinal CMS v5.1.0 was discovered to contain a remote code execution (RCE) vulnerability via the ActionEnter function.

  • CVE-2022-37204CriSep 20, 2022
    risk 0.64cvss 9.8epss 0.01

    Final CMS 5.1.0 is vulnerable to SQL Injection.

  • CVE-2022-37203CriSep 19, 2022
    risk 0.64cvss 9.8epss 0.01

    JFinal CMS 5.1.0 is vulnerable to SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection.

  • CVE-2022-37223CriAug 23, 2022
    risk 0.64cvss 9.8epss 0.01

    JFinal CMS 5.1.0 is vulnerable to SQL Injection via /jfinal_cms/system/role/list.

  • CVE-2022-37199CriAug 23, 2022
    risk 0.64cvss 9.8epss 0.01

    JFinal CMS 5.1.0 is vulnerable to SQL Injection via /jfinal_cms/system/user/list.

  • CVE-2022-30500CriMay 26, 2022
    risk 0.64cvss 9.8epss 0.01

    Jfinal cms 5.1.0 is vulnerable to SQL Injection.

  • CVE-2021-42242CriMay 5, 2022
    risk 0.64cvss 9.8epss 0.02

    A command execution vulnerability exists in jfinal_cms 5.0.1 via com.jflyfox.component.controller.Ueditor.

  • CVE-2020-19155HigSep 15, 2021
    risk 0.58cvss 8.8epss 0.08

    Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information and/or execute arbitrary code via the 'FileManager.rename()' function in the component 'modules/filemanager/FileManagerController.java'.

  • CVE-2020-19151HigSep 15, 2021
    risk 0.58cvss 8.8epss 0.05

    Command Injection in Jfinal CMS v4.7.1 and earlier allows remote attackers to execute arbitrary code by uploading a malicious HTML template file via the component 'jfinal_cms/admin/filemanager/list'.

  • CVE-2022-37202HigOct 26, 2022
    risk 0.57cvss 8.8epss 0.01

    JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/advicefeedback/list

  • CVE-2022-37208HigOct 13, 2022
    risk 0.57cvss 8.8epss 0.01

    JFinal CMS 5.1.0 is vulnerable to SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection.

  • CVE-2022-37209HigSep 27, 2022
    risk 0.57cvss 8.8epss 0.01

    JFinal CMS 5.1.0 is affected by: SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection.

  • CVE-2022-37205HigSep 20, 2022
    risk 0.57cvss 8.8epss 0.01

    JFinal CMS 5.1.0 is affected by: SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection.

  • CVE-2022-37201HigSep 15, 2022
    risk 0.57cvss 8.8epss 0.01

    JFinal CMS 5.1.0 is vulnerable to SQL Injection.

  • CVE-2022-37207HigSep 15, 2022
    risk 0.57cvss 8.8epss 0.01

    JFinal CMS 5.1.0 is affected by: SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection

  • CVE-2022-34928HigAug 3, 2022
    risk 0.57cvss 8.8epss 0.01

    JFinal CMS v5.1.0 was discovered to contain a SQL injection vulnerability via /system/user.

  • CVE-2020-19150HigSep 15, 2021
    risk 0.53cvss 8.1epss 0.03

    Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information or cause a denial of service via the 'FileManager.delete()' function in the component 'modules/filemanager/FileManagerController.java'.

  • CVE-2023-34645HigJun 16, 2023
    risk 0.49cvss 7.5epss 0.01

    jfinal CMS 5.1.0 has an arbitrary file read vulnerability.