CVE-2025-25772
- EPSS 0.02%
- Veröffentlicht 21.02.2025 19:15:14
- Zuletzt bearbeitet 09.07.2025 14:43:22
A Cross-Site Request Forgery (CSRF) in the component /back/UserController.java of Jspxcms v9.0 to v9.5 allows attackers to arbitrarily add Administrator accounts via a crafted request.
CVE-2024-1200
- EPSS 0.1%
- Veröffentlicht 03.02.2024 02:15:52
- Zuletzt bearbeitet 21.11.2024 08:50:01
A vulnerability was found in Jspxcms 10.2.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /template/1/default/. The manipulation leads to information disclosure. The attack may be launched remotely. T...
CVE-2024-0721
- EPSS 0.2%
- Veröffentlicht 19.01.2024 16:15:11
- Zuletzt bearbeitet 21.11.2024 08:47:13
A vulnerability has been found in Jspxcms 10.2.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Survey Label Handler. The manipulation leads to cross site scripting. The attack can be launch...
CVE-2023-46911
- EPSS 0.18%
- Veröffentlicht 01.11.2023 17:15:11
- Zuletzt bearbeitet 21.11.2024 08:29:28
There is a Cross Site Scripting (XSS) vulnerability in the choose_style_tree.do interface of Jspxcms v10.2.0 backend.
CVE-2018-16553
- EPSS 1.82%
- Veröffentlicht 20.06.2019 14:15:10
- Zuletzt bearbeitet 21.11.2024 03:52:57
In Jspxcms 9.0.0, a vulnerable URL routing implementation allows remote code execution after logging in as web admin.
CVE-2018-20596
- EPSS 0.36%
- Veröffentlicht 30.12.2018 18:29:00
- Zuletzt bearbeitet 21.11.2024 04:01:48
Jspxcms v9.0.0 allows SSRF.