Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
jflyfox jfinal cms 5.1.0 vulnerabilities and exploits
(subscribe to this query)
5.4
CVSSv3
CVE-2022-36527
Jfinal CMS v5.1.0 allows malicious users to execute arbitrary web scripts or HTML via a crafted payload injected into the post title text field under the publish blog module.
Jflyfox Jfinal Cms 5.1.0
9.8
CVSSv3
CVE-2023-30349
JFinal CMS v5.1.0 exists to contain a remote code execution (RCE) vulnerability via the ActionEnter function.
Jflyfox Jfinal Cms 5.1.0
7.2
CVSSv3
CVE-2022-38274
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/comment/list.
Jflyfox Jfinal Cms 5.1.0
7.2
CVSSv3
CVE-2022-38278
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/friendlylink/list.
Jflyfox Jfinal Cms 5.1.0
7.2
CVSSv3
CVE-2022-38280
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/image/list.
Jflyfox Jfinal Cms 5.1.0
7.2
CVSSv3
CVE-2022-38282
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/videoalbum/list.
Jflyfox Jfinal Cms 5.1.0
7.2
CVSSv3
CVE-2022-38283
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/video/list.
Jflyfox Jfinal Cms 5.1.0
7.2
CVSSv3
CVE-2022-38286
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /system/role/list.
Jflyfox Jfinal Cms 5.1.0
5.4
CVSSv3
CVE-2022-33113
Jfinal CMS v5.1.0 allows malicious users to execute arbitrary web scripts or HTML via a crafted payload injected into the keyword text field under the publish blog module.
Jflyfox Jfinal Cms 5.1.0
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-7073
CVE-2024-5496
CVE-2024-5495
XPath injection
bypass
CVE-2024-30043
CVE-2024-24919
denial of service
CVE-2024-35468
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4