VendorsJflyfoxjfinal_cmsall versions
Vulnerabilities

Jflyfox Jfinal CMS

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

51CVEs
CVE-2021-42242
A command execution vulnerability exists in jfinal_cms 5.0.1 via com.jflyfox.component.controller.Ueditor.
Published 2022-05-05 · Modified
9.8EPSS 0.020
CVE-2022-37203
JFinal CMS 5.1.0 is vulnerable to SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection.
Published 2022-09-19 · Modified
9.8EPSS 0.016
CVE-2023-30349
JFinal CMS v5.1.0 was discovered to contain a remote code execution (RCE) vulnerability via the ActionEnter function.
Published 2023-04-27 · Modified
9.8EPSS 0.016
CVE-2022-37204
Final CMS 5.1.0 is vulnerable to SQL Injection.
Published 2022-09-20 · Modified
9.8EPSS 0.014
CVE-2023-47503
An issue in jflyfox jfinalCMS v.5.1.0 allows a remote attacker to execute arbitrary code via a crafted script to the login.jsp component in the template management module.
Published 2023-11-28 · Modified
9.8EPSS 0.013
CVE-2022-30500
Jfinal cms 5.1.0 is vulnerable to SQL Injection.
Published 2022-05-26 · Modified
9.8EPSS 0.011
CVE-2022-37223
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /jfinal_cms/system/role/list.
Published 2022-08-23 · Modified
9.8EPSS 0.009
CVE-2022-37199
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /jfinal_cms/system/user/list.
Published 2022-08-23 · Modified
9.8EPSS 0.009
CVE-2024-53477
JFinal CMS 5.1.0 is vulnerable to Command Execution via unauthorized execution of deserialization in the file ApiForm.java
Published 2024-12-02 · Analyzed
9.8EPSS 0.009
CVE-2020-19155
Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information and/or execute arbitrary code via the 'FileManager.rename()' function in the component 'modules/filemanager/FileManagerController.java'.
Published 2021-09-15 · Modified
8.8EPSS 0.075
CVE-2020-19151
Command Injection in Jfinal CMS v4.7.1 and earlier allows remote attackers to execute arbitrary code by uploading a malicious HTML template file via the component 'jfinal_cms/admin/filemanager/list'.
Published 2021-09-15 · Modified
8.8EPSS 0.050
CVE-2022-37207
JFinal CMS 5.1.0 is affected by: SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection
Published 2022-09-15 · Modified
8.8EPSS 0.016
CVE-2022-37205
JFinal CMS 5.1.0 is affected by: SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection.
Published 2022-09-20 · Modified
8.8EPSS 0.016
CVE-2022-37201
JFinal CMS 5.1.0 is vulnerable to SQL Injection.
Published 2022-09-15 · Modified
8.8EPSS 0.016
CVE-2022-37209
JFinal CMS 5.1.0 is affected by: SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection.
Published 2022-09-27 · Modified
8.8EPSS 0.012
CVE-2022-37208
JFinal CMS 5.1.0 is vulnerable to SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection.
Published 2022-10-13 · Modified
8.8EPSS 0.012
CVE-2022-37202
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/advicefeedback/list
Published 2022-10-26 · Modified
8.8EPSS 0.011
CVE-2022-34928
JFinal CMS v5.1.0 was discovered to contain a SQL injection vulnerability via /system/user.
Published 2022-08-03 · Modified
8.8EPSS 0.009
CVE-2025-6105
jflyfox jfinal_cms HOME.java cross-site request forgery
Published 2025-06-16 · Analyzed
8.8EPSS 0.003
CVE-2020-19150
Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information or cause a denial of service via the 'FileManager.delete()' function in the component 'modules/filemanager/FileManagerController.java'.
Published 2021-09-15 · Modified
8.1EPSS 0.035
CVE-2021-40639
Improper access control in Jfinal CMS 5.1.0 allows attackers to access sensitive information via /classes/conf/db.properties&config=filemanager.config.js.
Published 2021-09-15 · Modified
7.5EPSS 0.012
CVE-2021-37262
JFinal_cms 5.1.0 is vulnerable to regex injection that may lead to Denial of Service.
Published 2021-12-16 · Modified
7.5EPSS 0.010
CVE-2023-34645
jfinal CMS 5.1.0 has an arbitrary file read vulnerability.
Published 2023-06-16 · Modified
7.5EPSS 0.008
CVE-2022-38275
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/contact/list.
Published 2022-09-09 · Modified
7.2EPSS 0.011
CVE-2022-38278
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/friendlylink/list.
Published 2022-09-09 · Modified
7.2EPSS 0.011
CVE-2022-38273
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/article/list_approve.
Published 2022-09-09 · Modified
7.2EPSS 0.010
CVE-2022-38274
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/comment/list.
Published 2022-09-09 · Modified
7.2EPSS 0.010
CVE-2022-38272
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/article/list.
Published 2022-09-09 · Modified
7.2EPSS 0.010
CVE-2022-38277
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/folderrollpicture/list.
Published 2022-09-09 · Modified
7.2EPSS 0.010
CVE-2022-38283
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/video/list.
Published 2022-09-09 · Modified
7.2EPSS 0.010
CVE-2022-38282
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/videoalbum/list.
Published 2022-09-09 · Modified
7.2EPSS 0.010
CVE-2022-38279
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/imagealbum/list.
Published 2022-09-09 · Modified
7.2EPSS 0.010
CVE-2022-38276
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/foldernotice/list.
Published 2022-09-09 · Modified
7.2EPSS 0.010
CVE-2022-38286
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /system/role/list.
Published 2022-09-09 · Modified
7.2EPSS 0.010
CVE-2022-38284
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /system/department/list.
Published 2022-09-09 · Modified
7.2EPSS 0.010
CVE-2022-38280
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/image/list.
Published 2022-09-09 · Modified
7.2EPSS 0.010
CVE-2022-38285
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /system/menu/list.
Published 2022-09-09 · Modified
7.2EPSS 0.010
CVE-2022-38281
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/site/list.
Published 2022-09-09 · Modified
7.2EPSS 0.010
CVE-2022-33114
Jfinal CMS v5.1.0 was discovered to contain a SQL injection vulnerability via the attrVal parameter at /jfinal_cms/system/dict/list.
Published 2022-06-23 · Modified
7.2EPSS 0.010
CVE-2022-28505
Jfinal_cms 5.1.0 is vulnerable to SQL Injection via com.jflyfox.system.log.LogController.java.
Published 2022-05-03 · Modified
7.2EPSS 0.010
1 / 2Next →