CVE-2026-2200
- EPSS 0.03%
- Veröffentlicht 09.02.2026 01:02:05
- Zuletzt bearbeitet 17.02.2026 19:01:38
A weakness has been identified in heyewei JFinalCMS 5.0.0. This affects an unknown function of the file /admin/admin/save of the component API Endpoint. Executing a manipulation can lead to cross site scripting. The attack can be launched remotely. T...
CVE-2024-57665
- EPSS 0.17%
- Veröffentlicht 29.01.2025 23:15:22
- Zuletzt bearbeitet 23.05.2025 14:50:35
JFinalCMS 1.0 is vulnerable to SQL Injection in rc/main/java/com/cms/entity/Content.java. The cause of the vulnerability is that the title parameter is controllable and is concatenated directly into filterSql without filtering.
CVE-2024-8782
- EPSS 0.12%
- Veröffentlicht 13.09.2024 18:15:07
- Zuletzt bearbeitet 19.09.2024 01:46:07
A vulnerability was found in JFinalCMS up to 1.0. It has been rated as critical. This issue affects the function delete of the file /admin/template/edit. The manipulation of the argument name leads to path traversal. The attack may be initiated remot...
CVE-2024-8706
- EPSS 1.05%
- Veröffentlicht 12.09.2024 00:15:02
- Zuletzt bearbeitet 05.06.2025 20:07:09
A vulnerability was found in JFinalCMS up to 20240903. It has been classified as problematic. This affects the function update of the file /admin/template/update of the component com.cms.util.TemplateUtils. The manipulation of the argument fileName l...
CVE-2024-8694
- EPSS 0.16%
- Veröffentlicht 11.09.2024 21:15:10
- Zuletzt bearbeitet 05.06.2025 20:05:25
A vulnerability, which was classified as problematic, was found in JFinalCMS up to 20240903. This affects the function update of the file /admin/template/update of the component com.cms.controller.admin.TemplateController. The manipulation of the arg...
CVE-2024-5379
- EPSS 0.96%
- Veröffentlicht 26.05.2024 22:15:09
- Zuletzt bearbeitet 05.06.2025 20:04:39
A vulnerability was found in JFinalCMS up to 20240111. It has been rated as problematic. This issue affects some unknown processing of the file /admin/template. The manipulation of the argument directory leads to cross site scripting. The attack may ...
CVE-2024-5310
- EPSS 0.74%
- Veröffentlicht 24.05.2024 09:15:09
- Zuletzt bearbeitet 05.06.2025 20:03:12
A vulnerability classified as problematic has been found in JFinalCMS up to 20221020. This affects an unknown part of the file /admin/content. The manipulation of the argument Title leads to cross site scripting. It is possible to initiate the attack...
CVE-2024-2568
- EPSS 0.17%
- Veröffentlicht 17.03.2024 23:15:05
- Zuletzt bearbeitet 19.05.2025 12:58:49
A vulnerability has been found in heyewei JFinalCMS 5.0.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/div_data/delete?divId=9 of the component Custom Data Page. The manipulation leads to s...