Show filters
3 Total Results
Displaying 1-3 of 3
Sort by:
Attacker Value
Unknown

CVE-2023-38948

Disclosure Date: August 03, 2023 (last updated October 08, 2023)
An arbitrary file download vulnerability in the /c/PluginsController.php component of jizhi CMS 1.9.5 allows attackers to execute arbitrary code via downloading a crafted plugin.
Attacker Value
Unknown

CVE-2021-36484

Disclosure Date: February 03, 2023 (last updated February 24, 2025)
SQL injection vulnerability in JIZHICMS 1.9.5 allows attackers to run arbitrary SQL commands via add or edit article page.
Attacker Value
Unknown

CVE-2022-27429

Disclosure Date: April 25, 2022 (last updated February 23, 2025)
Jizhicms v1.9.5 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability via /admin.php/Plugins/update.html.