VYPR

Vendor CVEs

Jflyfox

All CVEs

52 total · sorted by risk
  • CVE-2024-53477CriDec 2, 2024
    risk 0.64cvss 9.8epss 0.01

    JFinal CMS 5.1.0 is vulnerable to Command Execution via unauthorized execution of deserialization in the file ApiForm.java

  • CVE-2023-47503CriNov 28, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue in jflyfox jfinalCMS v.5.1.0 allows a remote attacker to execute arbitrary code via a crafted script to the login.jsp component in the template management module.

  • CVE-2023-30349CriApr 27, 2023
    risk 0.64cvss 9.8epss 0.02

    JFinal CMS v5.1.0 was discovered to contain a remote code execution (RCE) vulnerability via the ActionEnter function.

  • CVE-2022-37204CriSep 20, 2022
    risk 0.64cvss 9.8epss 0.01

    Final CMS 5.1.0 is vulnerable to SQL Injection.

  • CVE-2022-37203CriSep 19, 2022
    risk 0.64cvss 9.8epss 0.01

    JFinal CMS 5.1.0 is vulnerable to SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection.

  • CVE-2022-37223CriAug 23, 2022
    risk 0.64cvss 9.8epss 0.01

    JFinal CMS 5.1.0 is vulnerable to SQL Injection via /jfinal_cms/system/role/list.

  • CVE-2022-37199CriAug 23, 2022
    risk 0.64cvss 9.8epss 0.01

    JFinal CMS 5.1.0 is vulnerable to SQL Injection via /jfinal_cms/system/user/list.

  • CVE-2022-30500CriMay 26, 2022
    risk 0.64cvss 9.8epss 0.01

    Jfinal cms 5.1.0 is vulnerable to SQL Injection.

  • CVE-2021-42242CriMay 5, 2022
    risk 0.64cvss 9.8epss 0.02

    A command execution vulnerability exists in jfinal_cms 5.0.1 via com.jflyfox.component.controller.Ueditor.

  • CVE-2020-19155HigSep 15, 2021
    risk 0.58cvss 8.8epss 0.08

    Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information and/or execute arbitrary code via the 'FileManager.rename()' function in the component 'modules/filemanager/FileManagerController.java'.

  • CVE-2020-19151HigSep 15, 2021
    risk 0.58cvss 8.8epss 0.05

    Command Injection in Jfinal CMS v4.7.1 and earlier allows remote attackers to execute arbitrary code by uploading a malicious HTML template file via the component 'jfinal_cms/admin/filemanager/list'.

  • CVE-2022-37202HigOct 26, 2022
    risk 0.57cvss 8.8epss 0.01

    JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/advicefeedback/list

  • CVE-2022-37208HigOct 13, 2022
    risk 0.57cvss 8.8epss 0.01

    JFinal CMS 5.1.0 is vulnerable to SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection.

  • CVE-2022-37209HigSep 27, 2022
    risk 0.57cvss 8.8epss 0.01

    JFinal CMS 5.1.0 is affected by: SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection.

  • CVE-2022-37205HigSep 20, 2022
    risk 0.57cvss 8.8epss 0.01

    JFinal CMS 5.1.0 is affected by: SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection.

  • CVE-2022-37201HigSep 15, 2022
    risk 0.57cvss 8.8epss 0.01

    JFinal CMS 5.1.0 is vulnerable to SQL Injection.

  • CVE-2022-37207HigSep 15, 2022
    risk 0.57cvss 8.8epss 0.01

    JFinal CMS 5.1.0 is affected by: SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection

  • CVE-2022-34928HigAug 3, 2022
    risk 0.57cvss 8.8epss 0.01

    JFinal CMS v5.1.0 was discovered to contain a SQL injection vulnerability via /system/user.

  • CVE-2020-19150HigSep 15, 2021
    risk 0.53cvss 8.1epss 0.03

    Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information or cause a denial of service via the 'FileManager.delete()' function in the component 'modules/filemanager/FileManagerController.java'.

  • CVE-2023-34645HigJun 16, 2023
    risk 0.49cvss 7.5epss 0.01

    jfinal CMS 5.1.0 has an arbitrary file read vulnerability.

  • CVE-2021-37262HigDec 16, 2021
    risk 0.49cvss 7.5epss 0.01

    JFinal_cms 5.1.0 is vulnerable to regex injection that may lead to Denial of Service.

  • CVE-2021-40639HigSep 15, 2021
    risk 0.49cvss 7.5epss 0.01

    Improper access control in Jfinal CMS 5.1.0 allows attackers to access sensitive information via /classes/conf/db.properties&config=filemanager.config.js.

  • CVE-2022-38286HigSep 9, 2022
    risk 0.47cvss 7.2epss 0.01

    JFinal CMS 5.1.0 is vulnerable to SQL Injection via /system/role/list.

  • CVE-2022-38285HigSep 9, 2022
    risk 0.47cvss 7.2epss 0.01

    JFinal CMS 5.1.0 is vulnerable to SQL Injection via /system/menu/list.

  • CVE-2022-38284HigSep 9, 2022
    risk 0.47cvss 7.2epss 0.01

    JFinal CMS 5.1.0 is vulnerable to SQL Injection via /system/department/list.

  • CVE-2022-38283HigSep 9, 2022
    risk 0.47cvss 7.2epss 0.01

    JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/video/list.

  • CVE-2022-38282HigSep 9, 2022
    risk 0.47cvss 7.2epss 0.01

    JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/videoalbum/list.

  • CVE-2022-38281HigSep 9, 2022
    risk 0.47cvss 7.2epss 0.01

    JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/site/list.

  • CVE-2022-38280HigSep 9, 2022
    risk 0.47cvss 7.2epss 0.01

    JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/image/list.

  • CVE-2022-38279HigSep 9, 2022
    risk 0.47cvss 7.2epss 0.01

    JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/imagealbum/list.

  • CVE-2022-38278HigSep 9, 2022
    risk 0.47cvss 7.2epss 0.01

    JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/friendlylink/list.

  • CVE-2022-38277HigSep 9, 2022
    risk 0.47cvss 7.2epss 0.01

    JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/folderrollpicture/list.

  • CVE-2022-38276HigSep 9, 2022
    risk 0.47cvss 7.2epss 0.01

    JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/foldernotice/list.

  • CVE-2022-38275HigSep 9, 2022
    risk 0.47cvss 7.2epss 0.01

    JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/contact/list.

  • CVE-2022-38274HigSep 9, 2022
    risk 0.47cvss 7.2epss 0.01

    JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/comment/list.

  • CVE-2022-38273HigSep 9, 2022
    risk 0.47cvss 7.2epss 0.01

    JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/article/list_approve.

  • CVE-2022-38272HigSep 9, 2022
    risk 0.47cvss 7.2epss 0.01

    JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/article/list.

  • CVE-2022-33114HigJun 23, 2022
    risk 0.47cvss 7.2epss 0.01

    Jfinal CMS v5.1.0 was discovered to contain a SQL injection vulnerability via the attrVal parameter at /jfinal_cms/system/dict/list.

  • CVE-2022-28505HigMay 3, 2022
    risk 0.47cvss 7.2epss 0.01

    Jfinal_cms 5.1.0 is vulnerable to SQL Injection via com.jflyfox.system.log.LogController.java.

  • CVE-2020-19154MedSep 15, 2021
    risk 0.43cvss 6.5epss 0.04

    Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information via the 'FileManager.editFile()' function in the component 'modules/filemanager/FileManagerController.java'.

  • CVE-2020-19147MedSep 15, 2021
    risk 0.42cvss 6.5epss 0.02

    Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive infromation via the 'getFolder()' function in the component '/modules/filemanager/FileManager.java'.

  • CVE-2020-19146MedSep 15, 2021
    risk 0.42cvss 6.5epss 0.02

    Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information via the 'TemplatePath' parameter in the component 'jfinal_cms/admin/folder/list'.

  • CVE-2026-11473MedJun 8, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was identified in jflyfox jfinal_cms up to 5.1.0. This impacts the function list of the file AdvicefeedbackController.java. Such manipulation of the argument orderBy leads to sql injection. The attack can be launched remotely. The project was informed of the…

  • CVE-2023-22975MedFeb 3, 2023
    risk 0.40cvss 6.1epss 0.00

    A cross-site scripting (XSS) vulnerability in JFinal CMS v5.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the email parameter under /front/person/profile.html.

  • CVE-2023-24747MedApr 5, 2023
    risk 0.35cvss 5.4epss 0.00

    Jfinal CMS v5.1 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /system/dict/list.

  • CVE-2022-36527MedAug 25, 2022
    risk 0.35cvss 5.4epss 0.00

    Jfinal CMS v5.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the post title text field under the publish blog module.

  • CVE-2022-33113MedJun 23, 2022
    risk 0.35cvss 5.4epss 0.00

    Jfinal CMS v5.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the keyword text field under the publish blog module.

  • CVE-2022-29648MedJun 2, 2022
    risk 0.35cvss 5.4epss 0.00

    A cross-site scripting (XSS) vulnerability in Jfinal CMS v5.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted X-Forwarded-For request.

  • CVE-2022-27111MedApr 11, 2022
    risk 0.35cvss 5.4epss 0.00

    Jfinal_CMS 5.1.0 allows attackers to use the feedback function to send malicious XSS code to the administrator backend and execute it.

  • CVE-2021-46087MedJan 25, 2022
    risk 0.35cvss 5.4epss 0.01

    In jfinal_cms >= 5.1 0, there is a storage XSS vulnerability in the background system of CMS. Because developers do not filter the parameters submitted by the user input form, any user with background permission can affect the system security by entering malicious code.

Page 1 of 2