Jizhicms

Jizhicms

36 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.03%
  • Veröffentlicht 27.02.2026 05:02:06
  • Zuletzt bearbeitet 27.02.2026 18:32:50

A security vulnerability has been detected in jizhiCMS up to 2.5.6. Affected is the function findAll in the library frphp/lib/Model.php of the component Batch Interface. The manipulation of the argument data leads to sql injection. The attack is poss...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 17.02.2026 00:00:00
  • Zuletzt bearbeitet 19.02.2026 18:24:53

jizhicms 2.5.6 is vulnerable to SQL Injection in Article/deleteAll and Extmolds/deleteAll via the data parameter.

Exploit
  • EPSS 0.05%
  • Veröffentlicht 05.02.2026 16:13:29
  • Zuletzt bearbeitet 24.02.2026 21:22:33

jizhiCMS 1.6.7 contains a file download vulnerability in the admin plugins update endpoint that allows authenticated administrators to download arbitrary files. Attackers can exploit the vulnerability by sending crafted POST requests with malicious f...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 04.12.2025 18:02:05
  • Zuletzt bearbeitet 10.12.2025 21:40:58

A vulnerability was identified in JIZHICMS up to 2.5.5. The impacted element is an unknown function of the file /index.php/admins/Comment/addcomment.html of the component Comment Handler. The manipulation of the argument body leads to cross site scri...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 04.12.2025 17:32:08
  • Zuletzt bearbeitet 24.02.2026 06:16:16

A vulnerability was determined in JIZHICMS up to 2.5.5. The affected element is the function deleteAll/findAll/delete of the file /index.php/admins/Comment/deleteAll.html of the component Batch Delete Comments. Executing a manipulation can lead to sq...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 04.12.2025 17:32:06
  • Zuletzt bearbeitet 24.02.2026 06:16:16

A vulnerability was found in JIZHICMS up to 2.5.5. Impacted is the function commentlist of the file /index.php/admins/Comment/addcomment.html of the component Add Display Name Field. Performing a manipulation of the argument aid/tid results in sql in...

Exploit
  • EPSS 0.09%
  • Veröffentlicht 23.03.2025 02:31:04
  • Zuletzt bearbeitet 28.03.2025 19:33:14

A vulnerability has been found in JIZHICMS up to 1.7.0 and classified as problematic. This vulnerability affects unknown code of the file /user/release.html of the component Article Handler. The manipulation leads to improper authorization. The attac...

Exploit
  • EPSS 0.09%
  • Veröffentlicht 23.03.2025 01:31:04
  • Zuletzt bearbeitet 02.04.2025 15:39:07

A vulnerability, which was classified as problematic, was found in JIZHICMS up to 1.7.0. This affects an unknown part of the file /user/release.html of the component Article Handler. The manipulation of the argument ishot with the input 1 leads to im...

Exploit
  • EPSS 0.12%
  • Veröffentlicht 23.03.2025 00:15:26
  • Zuletzt bearbeitet 02.04.2025 15:37:24

A vulnerability, which was classified as problematic, has been found in JIZHICMS up to 1.7.0. Affected by this issue is some unknown functionality of the file /user/userinfo.html of the component Account Profile Page. The manipulation of the argument...

  • EPSS 0.11%
  • Veröffentlicht 26.02.2025 15:15:26
  • Zuletzt bearbeitet 10.04.2025 17:38:56

JizhiCMS v2.5.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the component \c\PluginsController.php. This vulnerability allows attackers to perform an intranet scan via a crafted request.