Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
jfinal jfinal vulnerabilities and exploits
(subscribe to this query)
7.2
CVSSv3
CVE-2022-28505
Jfinal_cms 5.1.0 is vulnerable to SQL Injection via com.jflyfox.system.log.LogController.java.
Jflyfox Jfinal Cms 5.1.0
6.5
CVSSv3
CVE-2020-19146
Improper Access Control in Jfinal CMS v4.7.1 and previous versions allows remote malicious users to obtain sensitive information via the 'TemplatePath' parameter in the component 'jfinal_cms/admin/folder/list'.
Jflyfox Jfinal Cms
6.5
CVSSv3
CVE-2020-19147
Improper Access Control in Jfinal CMS v4.7.1 and previous versions allows remote malicious users to obtain sensitive infromation via the 'getFolder()' function in the component '/modules/filemanager/FileManager.java'.
Jflyfox Jfinal Cms
6.5
CVSSv3
CVE-2020-19154
Improper Access Control in Jfinal CMS v4.7.1 and previous versions allows remote malicious users to obtain sensitive information via the 'FileManager.editFile()' function in the component 'modules/filemanager/FileManagerController.java'.
Jflyfox Jfinal Cms
6.1
CVSSv3
CVE-2023-22975
A cross-site scripting (XSS) vulnerability in JFinal CMS v5.1.0 allows malicious users to execute arbitrary web scripts or HTML via a crafted payload injected into the email parameter under /front/person/profile.html.
Jflyfox Jfinal Cms 5.1.0
6.1
CVSSv3
CVE-2021-33348
An issue exists in JFinal framework v4.9.10 and below. The "set" method of the "Controller" class of jfinal framework is not strictly filtered, which will lead to XSS vulnerabilities in some cases.
Jfinal Jfinal
5.4
CVSSv3
CVE-2023-24747
Jfinal CMS v5.1 exists to contain a cross-site scripting (XSS) vulnerability via the component /system/dict/list.
Jflyfox Jfinal Cms 5.1
5.4
CVSSv3
CVE-2022-36527
Jfinal CMS v5.1.0 allows malicious users to execute arbitrary web scripts or HTML via a crafted payload injected into the post title text field under the publish blog module.
Jflyfox Jfinal Cms 5.1.0
5.4
CVSSv3
CVE-2022-33113
Jfinal CMS v5.1.0 allows malicious users to execute arbitrary web scripts or HTML via a crafted payload injected into the keyword text field under the publish blog module.
Jflyfox Jfinal Cms 5.1.0
5.4
CVSSv3
CVE-2022-29648
A cross-site scripting (XSS) vulnerability in Jfinal CMS v5.1.0 allows malicious users to execute arbitrary web scripts or HTML via a crafted X-Forwarded-For request.
Jflyfox Jfinal Cms 5.1.0
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
firewall
CVE-2024-35649
stored XSS
CVE-2022-28654
CVE-2020-35153
CVE-2024-27348
CVE-2022-28652
local users
CVE-2017-3506
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
NEXT »