VYPR

Vendor CVEs

Jflyfox

All CVEs

52 total · sorted by risk
  • CVE-2020-19148MedSep 15, 2021
    risk 0.35cvss 5.4epss 0.01

    Cross Site Scripting (XSS) in Jfinal CMS v4.7.1 and earlier allows remote attackers to execute arbitrary code via the 'Nickname' parameter in the component '/jfinal_cms/front/person/profile.html'.

  • CVE-2025-6105MedJun 16, 2025
    risk 0.28cvss 4.3epss 0.00

    A vulnerability has been found in jflyfox jfinal_cms 5.0.1 and classified as problematic. This vulnerability affects unknown code of the file HOME.java. The manipulation of the argument Logout leads to cross-site request forgery. The attack can be initiated remotely. The exploit…

Page 2 of 2