VendorsHeyeweijfinalcmsall versions
Vulnerabilities

Heyewei JFinalCMS

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

8CVEs
CVE-2024-8782
JFinalCMS edit delete path traversal
Published 2024-09-13 · Analyzed
9.8EPSS 0.007
CVE-2024-57665
JFinalCMS 1.0 is vulnerable to SQL Injection in rc/main/java/com/cms/entity/Content.java. The cause of the vulnerability is that the title parameter is controllable and is concatenated directly into filterSql without filtering.
Published 2025-01-29 · Analyzed
9.8EPSS 0.005
CVE-2024-2568
heyewei JFinalCMS Custom Data Page sql injection
Published 2024-03-17 · Analyzed
7.2EPSS 0.007
CVE-2024-8706
JFinalCMS com.cms.util.TemplateUtils update path traversal
Published 2024-09-11 · Analyzed
6.5EPSS 0.007
CVE-2024-5379
JFinalCMS template cross site scripting
Published 2024-05-26 · Analyzed
5.4EPSS 0.004
CVE-2024-5310
JFinalCMS content cross site scripting
Published 2024-05-24 · Analyzed
5.4EPSS 0.004
CVE-2024-8694
JFinalCMS com.cms.controller.admin.TemplateController update path traversal
Published 2024-09-11 · Analyzed
5.1EPSS 0.008
CVE-2026-2200
heyewei JFinalCMS API Endpoint save cross site scripting
Published 2026-02-09 · Analyzed
4.8EPSS 0.002