Show filters
49 Total Results
Displaying 31-40 of 49
Sort by:
Attacker Value
Unknown

CVE-2022-37199

Disclosure Date: August 23, 2022 (last updated February 24, 2025)
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /jfinal_cms/system/user/list.
Attacker Value
Unknown

CVE-2022-34928

Disclosure Date: August 03, 2022 (last updated February 24, 2025)
JFinal CMS v5.1.0 was discovered to contain a SQL injection vulnerability via /system/user.
Attacker Value
Unknown

CVE-2022-33114

Disclosure Date: June 23, 2022 (last updated February 23, 2025)
Jfinal CMS v5.1.0 was discovered to contain a SQL injection vulnerability via the attrVal parameter at /jfinal_cms/system/dict/list.
Attacker Value
Unknown

CVE-2022-33113

Disclosure Date: June 23, 2022 (last updated February 23, 2025)
Jfinal CMS v5.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the keyword text field under the publish blog module.
Attacker Value
Unknown

CVE-2022-29648

Disclosure Date: June 02, 2022 (last updated February 23, 2025)
A cross-site scripting (XSS) vulnerability in Jfinal CMS v5.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted X-Forwarded-For request.
Attacker Value
Unknown

CVE-2022-30500

Disclosure Date: May 26, 2022 (last updated February 23, 2025)
Jfinal cms 5.1.0 is vulnerable to SQL Injection.
Attacker Value
Unknown

CVE-2021-42242

Disclosure Date: May 05, 2022 (last updated October 07, 2023)
A command execution vulnerability exists in jfinal_cms 5.0.1 via com.jflyfox.component.controller.Ueditor.
Attacker Value
Unknown

CVE-2022-28505

Disclosure Date: May 03, 2022 (last updated February 23, 2025)
Jfinal_cms 5.1.0 is vulnerable to SQL Injection via com.jflyfox.system.log.LogController.java.
Attacker Value
Unknown

CVE-2022-27111

Disclosure Date: April 11, 2022 (last updated February 23, 2025)
Jfinal_CMS 5.1.0 allows attackers to use the feedback function to send malicious XSS code to the administrator backend and execute it.
Attacker Value
Unknown

CVE-2021-46087

Disclosure Date: January 25, 2022 (last updated February 23, 2025)
In jfinal_cms >= 5.1 0, there is a storage XSS vulnerability in the background system of CMS. Because developers do not filter the parameters submitted by the user input form, any user with background permission can affect the system security by entering malicious code.