VYPR
Vendor

Jizhicms

Products
1
CVEs
40
Across products
40
Status
Private

Products

1

Recent CVEs

40
View all 40 CVEs →
  • CVE-2025-50229CriApr 23, 2026
    risk 0.64cvss 9.8epss 0.00

    Jizhicms v2.5.4 is vulnerable to SQL injection in the product editing module.

  • CVE-2025-25784CriFeb 26, 2025
    risk 0.64cvss 9.8epss 0.01

    An arbitrary file upload vulnerability in the component \c\TemplateController.php of Jizhicms v2.5.4 allows attackers to execute arbitrary code via uploading a crafted Zip file.

  • CVE-2024-32161CriApr 17, 2024
    risk 0.64cvss 9.8epss 0.01

    jizhiCMS 2.5 suffers from a File upload vulnerability.

  • CVE-2023-51154CriJan 4, 2024
    risk 0.64cvss 9.8epss 0.01

    Jizhicms v2.5 was discovered to contain an arbitrary file download vulnerability via the component /admin/c/PluginsController.php.

  • CVE-2021-36484CriFeb 3, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in JIZHICMS 1.9.5 allows attackers to run arbitrary SQL commands via add or edit article page.

  • CVE-2022-36578CriAug 19, 2022
    risk 0.64cvss 9.8epss 0.01

    jizhicms v2.3.1 has SQL injection in the background.

  • CVE-2022-27429CriApr 25, 2022
    risk 0.64cvss 9.8epss 0.01

    Jizhicms v1.9.5 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability via /admin.php/Plugins/update.html.

  • CVE-2025-25785CriFeb 26, 2025
    risk 0.59cvss 9.1epss 0.00

    JizhiCMS v2.5.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the component \c\PluginsController.php. This vulnerability allows attackers to perform an intranet scan via a crafted request.

  • CVE-2022-31393CriJun 9, 2022
    risk 0.59cvss 9.1epss 0.01

    Jizhicms v2.2.5 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability via the Index function in app/admin/c/PluginsController.php.

  • CVE-2022-31390CriJun 9, 2022
    risk 0.59cvss 9.1epss 0.01

    Jizhicms v2.2.5 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability via the Update function in app/admin/c/TemplateController.php.

  • CVE-2020-37117HigFeb 5, 2026
    risk 0.57cvss 8.8epss 0.01

    jizhiCMS 1.6.7 contains a file download vulnerability in the admin plugins update endpoint that allows authenticated administrators to download arbitrary files. Attackers can exploit the vulnerability by sending crafted POST requests with malicious filepath and download_url…

  • CVE-2023-50692HigDec 28, 2023
    risk 0.57cvss 8.8epss 0.01

    File Upload vulnerability in JIZHICMS v.2.5, allows remote attacker to execute arbitrary code via a crafted file uploaded and downloaded to the download_url parameter in the app/admin/exts/ directory.

  • CVE-2022-45278HigNov 23, 2022
    risk 0.57cvss 8.8epss 0.01

    Jizhicms v2.3.3 was discovered to contain a SQL injection vulnerability via the /index.php/admins/Fields/get_fields.html component.

  • CVE-2022-44140HigNov 23, 2022
    risk 0.57cvss 8.8epss 0.01

    Jizhicms v2.3.3 was discovered to contain a SQL injection vulnerability via the /Member/memberedit.html component.

  • CVE-2021-29334HigNov 23, 2022
    risk 0.57cvss 8.8epss 0.00

    An issue was discovered in JIZHI CMS 1.9.4. There is a CSRF vulnerability that can add an admin account via index, /admin.php/Admin/adminadd.html

  • CVE-2022-36577HigAug 19, 2022
    risk 0.57cvss 8.8epss 0.00

    An issue was discovered in jizhicms v2.3.1. There is a CSRF vulnerability that can add a admin.

  • CVE-2019-17593HigOct 14, 2019
    risk 0.57cvss 8.8epss 0.00

    JIZHICMS 1.5.1 allows admin.php/Admin/adminadd.html CSRF to add an administrator.

  • CVE-2025-50228CriApr 9, 2026
    risk 0.52cvss 9.1epss 0.00

    Jizhicms v2.5.4 is vulnerable to Server-Side Request Forgery (SSRF) in User Evaluation, Message, and Comment modules.

  • CVE-2024-33338HigApr 29, 2024
    risk 0.48cvss 7.3epss 0.01

    Cross Site Scripting vulnerability in jizhicms v.2.5.4 allows a remote attacker to obtain sensitive information via a crafted article publication request.

  • CVE-2025-70397HigFeb 17, 2026
    risk 0.47cvss 7.2epss 0.00

    jizhicms 2.5.6 is vulnerable to SQL Injection in Article/deleteAll and Extmolds/deleteAll via the data parameter.