Show filters
46 Total Results
Displaying 21-30 of 46
Sort by:
Attacker Value
Unknown
CVE-2023-50100
Disclosure Date: December 14, 2023 (last updated December 16, 2023)
JFinalcms 5.0.0 is vulnerable to Cross Site Scripting (XSS) via carousel image editing.
0
Attacker Value
Unknown
CVE-2023-50449
Disclosure Date: December 10, 2023 (last updated December 14, 2023)
JFinalCMS 5.0.0 could allow a remote attacker to read files via ../ Directory Traversal in the /common/down/file fileKey parameter.
0
Attacker Value
Unknown
CVE-2023-49487
Disclosure Date: December 08, 2023 (last updated December 13, 2023)
JFinalCMS v5.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the navigation management department.
0
Attacker Value
Unknown
CVE-2023-49486
Disclosure Date: December 08, 2023 (last updated December 13, 2023)
JFinalCMS v5.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the model management department.
0
Attacker Value
Unknown
CVE-2023-49485
Disclosure Date: December 08, 2023 (last updated December 13, 2023)
JFinalCMS v5.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the column management department.
0
Attacker Value
Unknown
CVE-2023-49448
Disclosure Date: December 05, 2023 (last updated December 09, 2023)
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via admin/nav/delete.
0
Attacker Value
Unknown
CVE-2023-49447
Disclosure Date: December 05, 2023 (last updated December 09, 2023)
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/nav/update.
0
Attacker Value
Unknown
CVE-2023-49446
Disclosure Date: December 05, 2023 (last updated December 09, 2023)
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/nav/save.
0
Attacker Value
Unknown
CVE-2023-49398
Disclosure Date: December 05, 2023 (last updated December 09, 2023)
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/category/delete.
0
Attacker Value
Unknown
CVE-2023-49397
Disclosure Date: December 05, 2023 (last updated December 09, 2023)
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/category/updateStatus.
0