CVE-2025-2639
- EPSS 0.37%
- Veröffentlicht 23.03.2025 02:31:04
- Zuletzt bearbeitet 28.03.2025 19:33:14
A vulnerability has been found in JIZHICMS up to 1.7.0 and classified as problematic. This vulnerability affects unknown code of the file /user/release.html of the component Article Handler. The manipulation leads to improper authorization. The attac...
CVE-2025-2638
- EPSS 0.37%
- Veröffentlicht 23.03.2025 01:31:04
- Zuletzt bearbeitet 02.04.2025 15:39:07
A vulnerability, which was classified as problematic, was found in JIZHICMS up to 1.7.0. This affects an unknown part of the file /user/release.html of the component Article Handler. The manipulation of the argument ishot with the input 1 leads to im...
CVE-2025-2637
- EPSS 0.39%
- Veröffentlicht 23.03.2025 00:15:26
- Zuletzt bearbeitet 02.04.2025 15:37:24
A vulnerability, which was classified as problematic, has been found in JIZHICMS up to 1.7.0. Affected by this issue is some unknown functionality of the file /user/userinfo.html of the component Account Profile Page. The manipulation of the argument...
CVE-2025-25785
- EPSS 0.41%
- Veröffentlicht 26.02.2025 15:15:26
- Zuletzt bearbeitet 10.04.2025 17:38:56
JizhiCMS v2.5.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the component \c\PluginsController.php. This vulnerability allows attackers to perform an intranet scan via a crafted request.
CVE-2025-25784
- EPSS 1%
- Veröffentlicht 26.02.2025 15:15:26
- Zuletzt bearbeitet 10.04.2025 17:42:20
An arbitrary file upload vulnerability in the component \c\TemplateController.php of Jizhicms v2.5.4 allows attackers to execute arbitrary code via uploading a crafted Zip file.
CVE-2024-34255
- EPSS 0.26%
- Veröffentlicht 08.05.2024 13:15:08
- Zuletzt bearbeitet 13.06.2025 13:00:45
jizhicms v2.5.1 contains a Cross-Site Scripting(XSS) vulnerability in the message function.
CVE-2024-33338
- EPSS 0.97%
- Veröffentlicht 29.04.2024 18:15:07
- Zuletzt bearbeitet 23.04.2025 01:28:50
Cross Site Scripting vulnerability in jizhicms v.2.5.4 allows a remote attacker to obtain sensitive information via a crafted article publication request.
CVE-2024-32161
- EPSS 0.75%
- Veröffentlicht 17.04.2024 18:15:16
- Zuletzt bearbeitet 18.04.2025 16:49:30
jizhiCMS 2.5 suffers from a File upload vulnerability.
CVE-2023-51154
- EPSS 0.61%
- Veröffentlicht 04.01.2024 19:15:08
- Zuletzt bearbeitet 18.06.2025 16:15:23
Jizhicms v2.5 was discovered to contain an arbitrary file download vulnerability via the component /admin/c/PluginsController.php.
CVE-2023-50692
- EPSS 0.94%
- Veröffentlicht 28.12.2023 06:15:44
- Zuletzt bearbeitet 17.04.2025 21:15:47
File Upload vulnerability in JIZHICMS v.2.5, allows remote attacker to execute arbitrary code via a crafted file uploaded and downloaded to the download_url parameter in the app/admin/exts/ directory.