Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
jflyfox vulnerabilities and exploits
(subscribe to this query)
5.4
CVSSv3
CVE-2022-27111
Jfinal_CMS 5.1.0 allows malicious users to use the feedback function to send malicious XSS code to the administrator backend and execute it.
Jflyfox Jfinal Cms 5.1.0
7.5
CVSSv3
CVE-2021-37262
JFinal_cms 5.1.0 is vulnerable to regex injection that may lead to Denial of Service.
Jflyfox Jfinal Cms 5.1.0
7.2
CVSSv3
CVE-2022-38280
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/image/list.
Jflyfox Jfinal Cms 5.1.0
7.2
CVSSv3
CVE-2022-38282
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/videoalbum/list.
Jflyfox Jfinal Cms 5.1.0
6.1
CVSSv3
CVE-2023-22975
A cross-site scripting (XSS) vulnerability in JFinal CMS v5.1.0 allows malicious users to execute arbitrary web scripts or HTML via a crafted payload injected into the email parameter under /front/person/profile.html.
Jflyfox Jfinal Cms 5.1.0
7.5
CVSSv3
CVE-2023-34645
jfinal CMS 5.1.0 has an arbitrary file read vulnerability.
Jflyfox Jfinal Cms 5.1.0
9.8
CVSSv3
CVE-2023-30349
JFinal CMS v5.1.0 exists to contain a remote code execution (RCE) vulnerability via the ActionEnter function.
Jflyfox Jfinal Cms 5.1.0
9.8
CVSSv3
CVE-2021-42242
A command execution vulnerability exists in jfinal_cms 5.0.1 via com.jflyfox.component.controller.Ueditor.
Jflyfox Jfinal Cms 5.0.1
9.8
CVSSv3
CVE-2023-47503
An issue in jflyfox jfinalCMS v.5.1.0 allows a remote malicious user to execute arbitrary code via a crafted script to the login.jsp component in the template management module.
Jflyfox Jfinal Cms 5.1.0
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
camera
bypass
CVE-2024-3592
CVE-2024-37383
CVE-2024-24919
CVE-2024-27822
CVE-2024-36788
CVE-2024-36789
man-in-the-middle
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5