CVE-2025-2637
- EPSS 0.12%
- Veröffentlicht 23.03.2025 00:15:26
- Zuletzt bearbeitet 02.04.2025 15:37:24
A vulnerability, which was classified as problematic, has been found in JIZHICMS up to 1.7.0. Affected by this issue is some unknown functionality of the file /user/userinfo.html of the component Account Profile Page. The manipulation of the argument...
CVE-2025-25785
- EPSS 0.15%
- Veröffentlicht 26.02.2025 15:15:26
- Zuletzt bearbeitet 10.04.2025 17:38:56
JizhiCMS v2.5.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the component \c\PluginsController.php. This vulnerability allows attackers to perform an intranet scan via a crafted request.
CVE-2025-25784
- EPSS 0.41%
- Veröffentlicht 26.02.2025 15:15:26
- Zuletzt bearbeitet 10.04.2025 17:42:20
An arbitrary file upload vulnerability in the component \c\TemplateController.php of Jizhicms v2.5.4 allows attackers to execute arbitrary code via uploading a crafted Zip file.
CVE-2024-34255
- EPSS 0.33%
- Veröffentlicht 08.05.2024 13:15:08
- Zuletzt bearbeitet 13.06.2025 13:00:45
jizhicms v2.5.1 contains a Cross-Site Scripting(XSS) vulnerability in the message function.
CVE-2024-33338
- EPSS 1.33%
- Veröffentlicht 29.04.2024 18:15:07
- Zuletzt bearbeitet 23.04.2025 01:28:50
Cross Site Scripting vulnerability in jizhicms v.2.5.4 allows a remote attacker to obtain sensitive information via a crafted article publication request.
CVE-2024-32161
- EPSS 0.15%
- Veröffentlicht 17.04.2024 18:15:16
- Zuletzt bearbeitet 18.04.2025 16:49:30
jizhiCMS 2.5 suffers from a File upload vulnerability.
CVE-2023-51154
- EPSS 0.09%
- Veröffentlicht 04.01.2024 19:15:08
- Zuletzt bearbeitet 18.06.2025 16:15:23
Jizhicms v2.5 was discovered to contain an arbitrary file download vulnerability via the component /admin/c/PluginsController.php.
CVE-2023-50692
- EPSS 1.84%
- Veröffentlicht 28.12.2023 06:15:44
- Zuletzt bearbeitet 17.04.2025 21:15:47
File Upload vulnerability in JIZHICMS v.2.5, allows remote attacker to execute arbitrary code via a crafted file uploaded and downloaded to the download_url parameter in the app/admin/exts/ directory.
CVE-2023-43836
- EPSS 0.06%
- Veröffentlicht 02.10.2023 21:15:34
- Zuletzt bearbeitet 21.11.2024 08:24:51
There is a SQL injection vulnerability in the Jizhicms 2.4.9 backend, which users can use to obtain database information
CVE-2023-38948
- EPSS 0.2%
- Veröffentlicht 03.08.2023 16:15:12
- Zuletzt bearbeitet 21.11.2024 08:14:30
An arbitrary file download vulnerability in the /c/PluginsController.php component of jizhi CMS 1.9.5 allows attackers to execute arbitrary code via downloading a crafted plugin.