Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
jflyfox jfinal cms 5.1.0 vulnerabilities and exploits
(subscribe to this query)
7.5
CVSSv2
CVE-2022-30500
Jfinal cms 5.1.0 is vulnerable to SQL Injection.
Jflyfox Jfinal Cms 5.1.0
6.5
CVSSv2
CVE-2022-33114
Jfinal CMS v5.1.0 exists to contain a SQL injection vulnerability via the attrVal parameter at /jfinal_cms/system/dict/list.
Jflyfox Jfinal Cms 5.1.0
6.5
CVSSv2
CVE-2022-28505
Jfinal_cms 5.1.0 is vulnerable to SQL Injection via com.jflyfox.system.log.LogController.java.
Jflyfox Jfinal Cms 5.1.0
5
CVSSv2
CVE-2021-37262
JFinal_cms 5.1.0 is vulnerable to regex injection that may lead to Denial of Service.
Jflyfox Jfinal Cms 5.1.0
5
CVSSv2
CVE-2021-40639
Improper access control in Jfinal CMS 5.1.0 allows malicious users to access sensitive information via /classes/conf/db.properties&config=filemanager.config.js.
Jflyfox Jfinal Cms 5.1.0
3.5
CVSSv2
CVE-2022-33113
Jfinal CMS v5.1.0 allows malicious users to execute arbitrary web scripts or HTML via a crafted payload injected into the keyword text field under the publish blog module.
Jflyfox Jfinal Cms 5.1.0
3.5
CVSSv2
CVE-2022-29648
A cross-site scripting (XSS) vulnerability in Jfinal CMS v5.1.0 allows malicious users to execute arbitrary web scripts or HTML via a crafted X-Forwarded-For request.
Jflyfox Jfinal Cms 5.1.0
3.5
CVSSv2
CVE-2022-27111
Jfinal_CMS 5.1.0 allows malicious users to use the feedback function to send malicious XSS code to the administrator backend and execute it.
Jflyfox Jfinal Cms 5.1.0
NA
CVE-2023-47503
An issue in jflyfox jfinalCMS v.5.1.0 allows a remote malicious user to execute arbitrary code via a crafted script to the login.jsp component in the template management module.
Jflyfox Jfinal Cms 5.1.0
NA
CVE-2023-34645
jfinal CMS 5.1.0 has an arbitrary file read vulnerability.
Jflyfox Jfinal Cms 5.1.0
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
firewall
CVE-2024-35649
stored XSS
CVE-2022-28654
CVE-2020-35153
CVE-2024-27348
CVE-2022-28652
local users
CVE-2017-3506
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
NEXT »