VYPR
Vendor

Jpressprojects

Products
1
CVEs
9
Across products
9
Status
Private

Products

1

Recent CVEs

9
  • CVE-2024-12348Dec 9, 2024
    risk 0.00cvss epss 0.00

    A vulnerability was found in Guizhou Xiaoma Technology jpress 5.1.2. It has been classified as problematic. Affected is the function AttachmentUtils.isUnSafe of the file /commons/attachment/upload of the component Attachment Upload Handler. The manipulation of the argument…

  • CVE-2024-11971Nov 28, 2024
    risk 0.00cvss epss 0.00

    A vulnerability classified as problematic was found in Guizhou Xiaoma Technology jpress 5.1.2. Affected by this vulnerability is an unknown functionality of the file /commons/attachment/upload of the component Avatar Handler. The manipulation of the argument files leads to cross…

  • CVE-2024-50919Nov 18, 2024
    risk 0.00cvss epss 0.01

    Jpress until v5.1.1 has arbitrary file uploads on the windows platform, and the construction of non-standard file formats such as .jsp. can lead to arbitrary command execution

  • CVE-2024-46468Oct 11, 2024
    risk 0.00cvss epss 0.00

    A Server-Side Request Forgery (SSRF) vulnerability exists in the jpress <= v5.1.1, which can be exploited by an attacker to obtain sensitive information, resulting in an information disclosure.

  • CVE-2024-8304Aug 29, 2024
    risk 0.00cvss epss 0.00

    A vulnerability has been found in jpress up to 5.1.1 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/template/edit of the component Template Module Handler. The manipulation leads to path traversal. The attack can be…

  • CVE-2024-43033Aug 22, 2024
    risk 0.00cvss epss 0.01

    JPress through 5.1.1 on Windows has an arbitrary file upload vulnerability that could cause arbitrary code execution via ::$DATA to AttachmentController, such as a .jsp::$DATA file to io.jpress.web.commons.controller.AttachmentController#upload. NOTE: this is unrelated to the…

  • CVE-2024-32358Apr 25, 2024
    risk 0.00cvss epss 0.01

    An issue in Jpress v.5.1.0 allows a remote attacker to execute arbitrary code via a crafted script to the custom plug-in module function, a different vulnerability than CVE-2024-43033.

  • CVE-2019-6278Jan 14, 2019
    risk 0.00cvss epss 0.00

    XSS exists in JPress v1.0.4 via Markdown input, or Markdown input with the code input option.

  • CVE-2018-19170Nov 11, 2018
    risk 0.00cvss epss 0.00

    In JPress v1.0-rc.5, there is stored XSS via each of the first three input fields to the starter-tomcat-1.0/admin/setting URI, as demonstrated by the web_name parameter.