Jflyfox / Jfinal Cms
52 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-11473 | jflyfox jfinal_cms AdvicefeedbackController.java list sql injection | MEDIUM | 5.3 | Jun 8, 2026 |
| CVE-2025-6105 | jflyfox jfinal_cms HOME.java cross-site request forgery | MEDIUM | 5.3 | Jun 16, 2025 |
| CVE-2024-53477 | JFinal CMS 5.1.0 is vulnerable to Command Execution via unauthorized execution of deserialization in the file ApiForm.java | CRITICAL | 9.8 | Dec 2, 2024 |
| CVE-2023-47503 | An issue in jflyfox jfinalCMS v.5.1.0 allows a remote attacker to execute arbitrary code via a crafted script to the login.jsp component in the template manage… | CRITICAL | 9.8 | Nov 28, 2023 |
| CVE-2023-34645 | jfinal CMS 5.1.0 has an arbitrary file read vulnerability. | HIGH | 7.5 | Jun 16, 2023 |
| CVE-2023-30349 | JFinal CMS v5.1.0 was discovered to contain a remote code execution (RCE) vulnerability via the ActionEnter function. | CRITICAL | 9.8 | Apr 27, 2023 |
| CVE-2023-24747 | Jfinal CMS v5.1 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /system/dict/list. | MEDIUM | 5.4 | Apr 5, 2023 |
| CVE-2023-22975 | A cross-site scripting (XSS) vulnerability in JFinal CMS v5.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into t… | MEDIUM | 6.1 | Feb 3, 2023 |
| CVE-2022-37202 | JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/advicefeedback/list | HIGH | 8.8 | Oct 26, 2022 |
| CVE-2022-37208 | JFinal CMS 5.1.0 is vulnerable to SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenat… | HIGH | 8.8 | Oct 13, 2022 |
| CVE-2022-37209 | JFinal CMS 5.1.0 is affected by: SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenati… | HIGH | 8.8 | Sep 27, 2022 |
| CVE-2022-37205 | JFinal CMS 5.1.0 is affected by: SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenati… | HIGH | 8.8 | Sep 20, 2022 |
| CVE-2022-37204 | Final CMS 5.1.0 is vulnerable to SQL Injection. | CRITICAL | 9.8 | Sep 20, 2022 |
| CVE-2022-37203 | JFinal CMS 5.1.0 is vulnerable to SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenat… | CRITICAL | 9.8 | Sep 19, 2022 |
| CVE-2022-37201 | JFinal CMS 5.1.0 is vulnerable to SQL Injection. | HIGH | 8.8 | Sep 15, 2022 |
| CVE-2022-37207 | JFinal CMS 5.1.0 is affected by: SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenati… | HIGH | 8.8 | Sep 15, 2022 |
| CVE-2022-38274 | JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/comment/list. | HIGH | 7.2 | Sep 9, 2022 |
| CVE-2022-38273 | JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/article/list_approve. | HIGH | 7.2 | Sep 9, 2022 |
| CVE-2022-38272 | JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/article/list. | HIGH | 7.2 | Sep 9, 2022 |
| CVE-2022-38275 | JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/contact/list. | HIGH | 7.2 | Sep 9, 2022 |
| CVE-2022-38277 | JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/folderrollpicture/list. | HIGH | 7.2 | Sep 9, 2022 |
| CVE-2022-38276 | JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/foldernotice/list. | HIGH | 7.2 | Sep 9, 2022 |
| CVE-2022-38278 | JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/friendlylink/list. | HIGH | 7.2 | Sep 9, 2022 |
| CVE-2022-38279 | JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/imagealbum/list. | HIGH | 7.2 | Sep 9, 2022 |
| CVE-2022-38281 | JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/site/list. | HIGH | 7.2 | Sep 9, 2022 |
Showing 1 to 25 of 52 CVEs