CVE-2024-8706
- EPSS 1.05%
- Veröffentlicht 12.09.2024 00:15:02
- Zuletzt bearbeitet 05.06.2025 20:07:09
A vulnerability was found in JFinalCMS up to 20240903. It has been classified as problematic. This affects the function update of the file /admin/template/update of the component com.cms.util.TemplateUtils. The manipulation of the argument fileName l...
CVE-2024-8694
- EPSS 0.16%
- Veröffentlicht 11.09.2024 21:15:10
- Zuletzt bearbeitet 05.06.2025 20:05:25
A vulnerability, which was classified as problematic, was found in JFinalCMS up to 20240903. This affects the function update of the file /admin/template/update of the component com.cms.controller.admin.TemplateController. The manipulation of the arg...
CVE-2024-40322
- EPSS 0.06%
- Veröffentlicht 16.07.2024 16:15:05
- Zuletzt bearbeitet 21.11.2024 09:30:59
An issue was discovered in JFinalCMS v.5.0.0. There is a SQL injection vulnerablity via /admin/div_data/data
CVE-2024-5379
- EPSS 0.96%
- Veröffentlicht 26.05.2024 22:15:09
- Zuletzt bearbeitet 05.06.2025 20:04:39
A vulnerability was found in JFinalCMS up to 20240111. It has been rated as problematic. This issue affects some unknown processing of the file /admin/template. The manipulation of the argument directory leads to cross site scripting. The attack may ...
CVE-2023-51254
- EPSS 0.46%
- Veröffentlicht 29.04.2024 18:15:07
- Zuletzt bearbeitet 23.04.2025 01:27:18
Cross Site Scripting vulnerability in Jfinalcms v.5.0.0 allows a remote attacker to execute arbitrary code via a crafted script to the friendship link component.
CVE-2024-2568
- EPSS 0.17%
- Veröffentlicht 17.03.2024 23:15:05
- Zuletzt bearbeitet 19.05.2025 12:58:49
A vulnerability has been found in heyewei JFinalCMS 5.0.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/div_data/delete?divId=9 of the component Custom Data Page. The manipulation leads to s...
CVE-2024-24375
- EPSS 0.07%
- Veröffentlicht 07.03.2024 01:15:52
- Zuletzt bearbeitet 30.04.2025 16:53:47
SQL injection vulnerability in Jfinalcms v.5.0.0 allows a remote attacker to obtain sensitive information via /admin/admin name parameter.
CVE-2024-24029
- EPSS 0.06%
- Veröffentlicht 02.02.2024 16:15:55
- Zuletzt bearbeitet 12.06.2025 15:15:36
JFinalCMS 5.0.0 is vulnerable to SQL injection via /admin/content/data.
CVE-2024-22497
- EPSS 0.13%
- Veröffentlicht 23.01.2024 19:15:08
- Zuletzt bearbeitet 30.05.2025 15:15:32
Cross Site Scripting (XSS) vulnerability in /admin/login password parameter in JFinalcms 5.0.0 allows attackers to run arbitrary code via crafted URL.
CVE-2024-22496
- EPSS 0.13%
- Veröffentlicht 23.01.2024 17:15:10
- Zuletzt bearbeitet 05.06.2025 17:15:28
Cross Site Scripting (XSS) vulnerability in JFinalcms 5.0.0 allows attackers to run arbitrary code via the /admin/login username parameter.