Jfinalcms Project

Jfinalcms

43 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 1.05%
  • Veröffentlicht 12.09.2024 00:15:02
  • Zuletzt bearbeitet 05.06.2025 20:07:09

A vulnerability was found in JFinalCMS up to 20240903. It has been classified as problematic. This affects the function update of the file /admin/template/update of the component com.cms.util.TemplateUtils. The manipulation of the argument fileName l...

Exploit
  • EPSS 0.16%
  • Veröffentlicht 11.09.2024 21:15:10
  • Zuletzt bearbeitet 05.06.2025 20:05:25

A vulnerability, which was classified as problematic, was found in JFinalCMS up to 20240903. This affects the function update of the file /admin/template/update of the component com.cms.controller.admin.TemplateController. The manipulation of the arg...

Exploit
  • EPSS 0.06%
  • Veröffentlicht 16.07.2024 16:15:05
  • Zuletzt bearbeitet 21.11.2024 09:30:59

An issue was discovered in JFinalCMS v.5.0.0. There is a SQL injection vulnerablity via /admin/div_data/data

Exploit
  • EPSS 0.96%
  • Veröffentlicht 26.05.2024 22:15:09
  • Zuletzt bearbeitet 05.06.2025 20:04:39

A vulnerability was found in JFinalCMS up to 20240111. It has been rated as problematic. This issue affects some unknown processing of the file /admin/template. The manipulation of the argument directory leads to cross site scripting. The attack may ...

Exploit
  • EPSS 0.46%
  • Veröffentlicht 29.04.2024 18:15:07
  • Zuletzt bearbeitet 23.04.2025 01:27:18

Cross Site Scripting vulnerability in Jfinalcms v.5.0.0 allows a remote attacker to execute arbitrary code via a crafted script to the friendship link component.

Exploit
  • EPSS 0.17%
  • Veröffentlicht 17.03.2024 23:15:05
  • Zuletzt bearbeitet 19.05.2025 12:58:49

A vulnerability has been found in heyewei JFinalCMS 5.0.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/div_data/delete?divId=9 of the component Custom Data Page. The manipulation leads to s...

Exploit
  • EPSS 0.07%
  • Veröffentlicht 07.03.2024 01:15:52
  • Zuletzt bearbeitet 30.04.2025 16:53:47

SQL injection vulnerability in Jfinalcms v.5.0.0 allows a remote attacker to obtain sensitive information via /admin/admin name parameter.

Exploit
  • EPSS 0.06%
  • Veröffentlicht 02.02.2024 16:15:55
  • Zuletzt bearbeitet 12.06.2025 15:15:36

JFinalCMS 5.0.0 is vulnerable to SQL injection via /admin/content/data.

Exploit
  • EPSS 0.13%
  • Veröffentlicht 23.01.2024 19:15:08
  • Zuletzt bearbeitet 30.05.2025 15:15:32

Cross Site Scripting (XSS) vulnerability in /admin/login password parameter in JFinalcms 5.0.0 allows attackers to run arbitrary code via crafted URL.

Exploit
  • EPSS 0.13%
  • Veröffentlicht 23.01.2024 17:15:10
  • Zuletzt bearbeitet 05.06.2025 17:15:28

Cross Site Scripting (XSS) vulnerability in JFinalcms 5.0.0 allows attackers to run arbitrary code via the /admin/login username parameter.