Search Results (Refine Search)
- Results Type: Overview
- Keyword (text search): cpe:2.3:a:jflyfox:jfinal_cms:5.1.0:*:*:*:*:*:*:*
- CPE Name Search: true
Vuln ID | Summary | CVSS Severity |
---|---|---|
CVE-2023-47503 |
An issue in jflyfox jfinalCMS v.5.1.0 allows a remote attacker to execute arbitrary code via a crafted script to the login.jsp component in the template management module. Published: November 27, 2023; 9:15:42 PM -0500 |
V4.0:(not available) V3.1: 9.8 CRITICAL V2.0:(not available) |
CVE-2023-34645 |
jfinal CMS 5.1.0 has an arbitrary file read vulnerability. Published: June 16, 2023; 2:15:09 PM -0400 |
V4.0:(not available) V3.1: 7.5 HIGH V2.0:(not available) |
CVE-2023-30349 |
JFinal CMS v5.1.0 was discovered to contain a remote code execution (RCE) vulnerability via the ActionEnter function. Published: April 27, 2023; 10:15:09 AM -0400 |
V4.0:(not available) V3.1: 9.8 CRITICAL V2.0:(not available) |
CVE-2023-22975 |
A cross-site scripting (XSS) vulnerability in JFinal CMS v5.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the email parameter under /front/person/profile.html. Published: February 03, 2023; 12:15:09 PM -0500 |
V4.0:(not available) V3.1: 6.1 MEDIUM V2.0:(not available) |
CVE-2022-37202 |
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/advicefeedback/list Published: October 26, 2022; 2:15:10 PM -0400 |
V4.0:(not available) V3.1: 8.8 HIGH V2.0:(not available) |
CVE-2022-37208 |
JFinal CMS 5.1.0 is vulnerable to SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection. Published: October 13, 2022; 8:15:11 AM -0400 |
V4.0:(not available) V3.1: 8.8 HIGH V2.0:(not available) |
CVE-2022-37209 |
JFinal CMS 5.1.0 is affected by: SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection. Published: September 27, 2022; 7:15:14 PM -0400 |
V4.0:(not available) V3.1: 8.8 HIGH V2.0:(not available) |
CVE-2022-37205 |
JFinal CMS 5.1.0 is affected by: SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection. Published: September 20, 2022; 2:15:10 PM -0400 |
V4.0:(not available) V3.1: 8.8 HIGH V2.0:(not available) |
CVE-2022-37204 |
Final CMS 5.1.0 is vulnerable to SQL Injection. Published: September 20, 2022; 1:15:09 PM -0400 |
V4.0:(not available) V3.1: 9.8 CRITICAL V2.0:(not available) |
CVE-2022-37203 |
JFinal CMS 5.1.0 is vulnerable to SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection. Published: September 19, 2022; 12:15:11 PM -0400 |
V4.0:(not available) V3.1: 9.8 CRITICAL V2.0:(not available) |
CVE-2022-37201 |
JFinal CMS 5.1.0 is vulnerable to SQL Injection. Published: September 15, 2022; 12:15:10 PM -0400 |
V4.0:(not available) V3.1: 8.8 HIGH V2.0:(not available) |
CVE-2022-37207 |
JFinal CMS 5.1.0 is affected by: SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection Published: September 15, 2022; 11:15:09 AM -0400 |
V4.0:(not available) V3.1: 8.8 HIGH V2.0:(not available) |
CVE-2022-38286 |
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /system/role/list. Published: September 09, 2022; 10:15:09 AM -0400 |
V4.0:(not available) V3.1: 7.2 HIGH V2.0:(not available) |
CVE-2022-38285 |
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /system/menu/list. Published: September 09, 2022; 10:15:09 AM -0400 |
V4.0:(not available) V3.1: 7.2 HIGH V2.0:(not available) |
CVE-2022-38284 |
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /system/department/list. Published: September 09, 2022; 10:15:09 AM -0400 |
V4.0:(not available) V3.1: 7.2 HIGH V2.0:(not available) |
CVE-2022-38283 |
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/video/list. Published: September 09, 2022; 10:15:09 AM -0400 |
V4.0:(not available) V3.1: 7.2 HIGH V2.0:(not available) |
CVE-2022-38282 |
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/videoalbum/list. Published: September 09, 2022; 10:15:09 AM -0400 |
V4.0:(not available) V3.1: 7.2 HIGH V2.0:(not available) |
CVE-2022-38281 |
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/site/list. Published: September 09, 2022; 10:15:09 AM -0400 |
V4.0:(not available) V3.1: 7.2 HIGH V2.0:(not available) |
CVE-2022-38280 |
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/image/list. Published: September 09, 2022; 10:15:09 AM -0400 |
V4.0:(not available) V3.1: 7.2 HIGH V2.0:(not available) |
CVE-2022-38279 |
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/imagealbum/list. Published: September 09, 2022; 10:15:09 AM -0400 |
V4.0:(not available) V3.1: 7.2 HIGH V2.0:(not available) |