Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
jflyfox jfinal cms vulnerabilities and exploits
(subscribe to this query)
7.5
CVSSv3
CVE-2023-34645
jfinal CMS 5.1.0 has an arbitrary file read vulnerability.
Jflyfox Jfinal Cms 5.1.0
5.4
CVSSv3
CVE-2022-36527
Jfinal CMS v5.1.0 allows malicious users to execute arbitrary web scripts or HTML via a crafted payload injected into the post title text field under the publish blog module.
Jflyfox Jfinal Cms 5.1.0
6.1
CVSSv3
CVE-2023-22975
A cross-site scripting (XSS) vulnerability in JFinal CMS v5.1.0 allows malicious users to execute arbitrary web scripts or HTML via a crafted payload injected into the email parameter under /front/person/profile.html.
Jflyfox Jfinal Cms 5.1.0
5.4
CVSSv3
CVE-2023-24747
Jfinal CMS v5.1 exists to contain a cross-site scripting (XSS) vulnerability via the component /system/dict/list.
Jflyfox Jfinal Cms 5.1
7.2
CVSSv3
CVE-2022-38272
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/article/list.
Jflyfox Jfinal Cms 5.1.0
7.2
CVSSv3
CVE-2022-38273
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/article/list_approve.
Jflyfox Jfinal Cms 5.1.0
7.2
CVSSv3
CVE-2022-38275
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/contact/list.
Jflyfox Jfinal Cms 5.1.0
7.2
CVSSv3
CVE-2022-38276
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/foldernotice/list.
Jflyfox Jfinal Cms 5.1.0
7.2
CVSSv3
CVE-2022-38277
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/folderrollpicture/list.
Jflyfox Jfinal Cms 5.1.0
7.2
CVSSv3
CVE-2022-38278
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/friendlylink/list.
Jflyfox Jfinal Cms 5.1.0
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
inject
CVE-2024-34001
CVE-2024-37018
LFI
CVE-2024-1275
CVE-2024-1086
CSRF
CVE-2024-31030
CVE-2024-24919
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
NEXT »