Home/Product/jflyfox jfinal cms
Product

jflyfox jfinal cms

101 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-2200
all versions
A weakness has been identified in heyewei JFinalCMS 5.0.0. This affects an unknown function of the file /admin/admin/save of the c
2.4LOW
CVE-2025-6105
all versions
A vulnerability has been found in jflyfox jfinal_cms 5.0.1 and classified as problematic. This vulnerability affects unknown code
4.3MEDIUM
CVE-2024-57665
all versions
JFinalCMS 1.0 is vulnerable to SQL Injection in rc/main/java/com/cms/entity/Content.java. The cause of the vulnerability is that t
9.8CRITICAL
CVE-2024-12351
all versions
A vulnerability classified as critical has been found in JFinalCMS 1.0. This affects the function findPage of the file src\main\ja
6.3MEDIUM
CVE-2024-12350
all versions
A vulnerability was found in JFinalCMS 1.0. It has been rated as critical. Affected by this issue is the function update of the fi
6.3MEDIUM
CVE-2024-12349
all versions
A vulnerability was found in JFinalCMS 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown func
4.3MEDIUM
CVE-2024-53477
all versions
JFinal CMS 5.1.0 is vulnerable to Command Execution via unauthorized execution of deserialization in the file ApiForm.java
9.8CRITICAL
CVE-2024-8782
<= 1.0
A vulnerability was found in JFinalCMS up to 1.0. It has been rated as critical. This issue affects the function delete of the fil
6.3MEDIUM
CVE-2024-8706
< 20240903
A vulnerability was found in JFinalCMS up to 20240903. It has been classified as problematic. This affects the function update of
4.3MEDIUM
CVE-2024-8694
< 20240903
A vulnerability, which was classified as problematic, was found in JFinalCMS up to 20240903. This affects the function update of t
3.8LOW
CVE-2024-40322
all versions
An issue was discovered in JFinalCMS v.5.0.0. There is a SQL injection vulnerablity via /admin/div_data/data
8.8HIGH
CVE-2024-5379
< 20240111
A vulnerability was found in JFinalCMS up to 20240111. It has been rated as problematic. This issue affects some unknown processin
3.5LOW
CVE-2024-5310
< 20221020
A vulnerability classified as problematic has been found in JFinalCMS up to 20221020. This affects an unknown part of the file /ad
2.4LOW
CVE-2023-51254
all versions
Cross Site Scripting vulnerability in Jfinalcms v.5.0.0 allows a remote attacker to execute arbitrary code via a crafted script to
6.1MEDIUM
CVE-2024-2568
all versions
A vulnerability has been found in heyewei JFinalCMS 5.0.0 and classified as critical. Affected by this vulnerability is an unknown
4.7MEDIUM
CVE-2024-24375
all versions
SQL injection vulnerability in Jfinalcms v.5.0.0 allows a remote attacker to obtain sensitive information via /admin/admin name pa
7.5HIGH
CVE-2024-24029
all versions
JFinalCMS 5.0.0 is vulnerable to SQL injection via /admin/content/data.
9.8CRITICAL
CVE-2024-22497
all versions
Cross Site Scripting (XSS) vulnerability in /admin/login password parameter in JFinalcms 5.0.0 allows attackers to run arbitrary c
6.1MEDIUM
CVE-2024-22496
all versions
Cross Site Scripting (XSS) vulnerability in JFinalcms 5.0.0 allows attackers to run arbitrary code via the /admin/login username p
6.1MEDIUM
CVE-2024-22494
all versions
A stored XSS vulnerability exists in JFinalcms 5.0.0 via the /gusetbook/save mobile parameter, which allows remote attackers to in
5.4MEDIUM
CVE-2024-22493
all versions
A stored XSS vulnerability exists in JFinalcms 5.0.0 via the /gusetbook/save content parameter, which allows remote attackers to i
5.4MEDIUM
CVE-2024-22492
all versions
A stored XSS vulnerability exists in JFinalcms 5.0.0 via the /gusetbook/save contact parameter, which allows remote attackers to i
5.4MEDIUM
CVE-2023-50136
all versions
Cross Site Scripting (XSS) vulnerability in JFinalcms 5.0.0 allows attackers to run arbitrary code via the name field when creatin
5.4MEDIUM
CVE-2023-50137
all versions
JFinalcms 5.0.0 is vulnerable to Cross Site Scripting (XSS) in the site management office.
5.4MEDIUM
CVE-2023-50102
all versions
JFinalcms 5.0.0 is vulnerable to Cross Site Scripting (XSS).
5.4MEDIUM
CVE-2023-50101
all versions
JFinalcms 5.0.0 is vulnerable to Cross Site Scripting (XSS) via Label management editing.
5.4MEDIUM
CVE-2023-50100
all versions
JFinalcms 5.0.0 is vulnerable to Cross Site Scripting (XSS) via carousel image editing.
5.4MEDIUM
CVE-2023-50449
all versions
JFinalCMS 5.0.0 could allow a remote attacker to read files via ../ Directory Traversal in the /common/down/file fileKey parameter
7.5HIGH
CVE-2023-49487
all versions
JFinalCMS v5.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the navigation management department.
5.4MEDIUM
CVE-2023-49486
all versions
JFinalCMS v5.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the model management department.
5.4MEDIUM
CVE-2023-49485
all versions
JFinalCMS v5.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the column management department.
5.4MEDIUM
CVE-2023-49448
all versions
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via admin/nav/delete.
8.8HIGH
CVE-2023-49447
all versions
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/nav/update.
8.8HIGH
CVE-2023-49446
all versions
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/nav/save.
8.8HIGH
CVE-2023-49398
all versions
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/category/delete.
8.8HIGH
CVE-2023-49397
all versions
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/category/updateStatus.
8.8HIGH
CVE-2023-49396
all versions
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/category/save.
8.8HIGH
CVE-2023-49395
all versions
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/category/update.
8.8HIGH
CVE-2023-49383
all versions
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/tag/save.
8.8HIGH
CVE-2023-49382
all versions
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/div/delete.
8.8HIGH
CVE-2023-49381
all versions
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/div/update.
8.8HIGH
CVE-2023-49380
all versions
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/friend_link/delete.
8.8HIGH
CVE-2023-49379
all versions
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /admin/friend_link/
8.8HIGH
CVE-2023-49378
all versions
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/form/save.
8.8HIGH
CVE-2023-49377
all versions
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/tag/update.
8.8HIGH
CVE-2023-49376
all versions
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/tag/delete.
8.8HIGH
CVE-2023-49375
all versions
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/friend_link/update.
8.8HIGH
CVE-2023-49374
all versions
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/slide/update.
8.8HIGH
CVE-2023-49373
all versions
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/slide/delete.
8.8HIGH
CVE-2023-49372
all versions
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/slide/save.
8.8HIGH
CVE-2023-47503
all versions
An issue in jflyfox jfinalCMS v.5.1.0 allows a remote attacker to execute arbitrary code via a crafted script to the login.jsp com
9.8CRITICAL
CVE-2023-41599
all versions
An issue in the component /common/DownController.java of JFinalCMS v5.0.0 allows attackers to execute a directory traversal.
5.3MEDIUM
CVE-2023-34645
all versions
jfinal CMS 5.1.0 has an arbitrary file read vulnerability.
7.5HIGH
CVE-2023-30349
all versions
JFinal CMS v5.1.0 was discovered to contain a remote code execution (RCE) vulnerability via the ActionEnter function.
9.8CRITICAL
CVE-2023-24747
all versions
Jfinal CMS v5.1 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /system/dict/list.
5.4MEDIUM
CVE-2023-22975
all versions
A cross-site scripting (XSS) vulnerability in JFinal CMS v5.1.0 allows attackers to execute arbitrary web scripts or HTML via a cr
6.1MEDIUM
CVE-2022-37202
all versions
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/advicefeedback/list
8.8HIGH
CVE-2022-37208
all versions
JFinal CMS 5.1.0 is vulnerable to SQL Injection. These interfaces do not use the same component, nor do they have filters, but eac
8.8HIGH
CVE-2022-37209
all versions
JFinal CMS 5.1.0 is affected by: SQL Injection. These interfaces do not use the same component, nor do they have filters, but each
8.8HIGH
CVE-2022-37205
all versions
JFinal CMS 5.1.0 is affected by: SQL Injection. These interfaces do not use the same component, nor do they have filters, but each
8.8HIGH
CVE-2022-37204
all versions
Final CMS 5.1.0 is vulnerable to SQL Injection.
9.8CRITICAL
CVE-2022-37203
all versions
JFinal CMS 5.1.0 is vulnerable to SQL Injection. These interfaces do not use the same component, nor do they have filters, but eac
9.8CRITICAL
CVE-2022-37201
all versions
JFinal CMS 5.1.0 is vulnerable to SQL Injection.
8.8HIGH
CVE-2022-37207
all versions
JFinal CMS 5.1.0 is affected by: SQL Injection. These interfaces do not use the same component, nor do they have filters, but each
8.8HIGH
CVE-2022-38286
all versions
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /system/role/list.
7.2HIGH
CVE-2022-38285
all versions
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /system/menu/list.
7.2HIGH
CVE-2022-38284
all versions
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /system/department/list.
7.2HIGH
CVE-2022-38283
all versions
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/video/list.
7.2HIGH
CVE-2022-38282
all versions
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/videoalbum/list.
7.2HIGH
CVE-2022-38281
all versions
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/site/list.
7.2HIGH
CVE-2022-38280
all versions
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/image/list.
7.2HIGH
CVE-2022-38279
all versions
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/imagealbum/list.
7.2HIGH
CVE-2022-38278
all versions
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/friendlylink/list.
7.2HIGH
CVE-2022-38277
all versions
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/folderrollpicture/list.
7.2HIGH
CVE-2022-38276
all versions
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/foldernotice/list.
7.2HIGH
CVE-2022-38275
all versions
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/contact/list.
7.2HIGH
CVE-2022-38274
all versions
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/comment/list.
7.2HIGH
CVE-2022-38273
all versions
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/article/list_approve.
7.2HIGH
CVE-2022-38272
all versions
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/article/list.
7.2HIGH
CVE-2022-36527
all versions
Jfinal CMS v5.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the post title tex
5.4MEDIUM
CVE-2022-37223
all versions
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /jfinal_cms/system/role/list.
9.8CRITICAL
CVE-2022-37199
all versions
JFinal CMS 5.1.0 is vulnerable to SQL Injection via /jfinal_cms/system/user/list.
9.8CRITICAL
CVE-2022-34928
all versions
JFinal CMS v5.1.0 was discovered to contain a SQL injection vulnerability via /system/user.
8.8HIGH
CVE-2022-33114
all versions
Jfinal CMS v5.1.0 was discovered to contain a SQL injection vulnerability via the attrVal parameter at /jfinal_cms/system/dict/lis
7.2HIGH
CVE-2022-33113
all versions
Jfinal CMS v5.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the keyword text f
5.4MEDIUM
CVE-2022-29648
all versions
A cross-site scripting (XSS) vulnerability in Jfinal CMS v5.1.0 allows attackers to execute arbitrary web scripts or HTML via a cr
5.4MEDIUM
CVE-2022-30500
all versions
Jfinal cms 5.1.0 is vulnerable to SQL Injection.
9.8CRITICAL
CVE-2021-42242
all versions
A command execution vulnerability exists in jfinal_cms 5.0.1 via com.jflyfox.component.controller.Ueditor.
9.8CRITICAL
CVE-2022-28505
all versions
Jfinal_cms 5.1.0 is vulnerable to SQL Injection via com.jflyfox.system.log.LogController.java.
7.2HIGH
CVE-2022-27341
all versions
JFinalCMS v2.0 was discovered to contain a SQL injection vulnerability via the Article Management function.
9.8CRITICAL
CVE-2022-27111
all versions
Jfinal_CMS 5.1.0 allows attackers to use the feedback function to send malicious XSS code to the administrator backend and execute
5.4MEDIUM
CVE-2021-46087
>= 5.1.0
In jfinal_cms >= 5.1 0, there is a storage XSS vulnerability in the background system of CMS. Because developers do not filter the
5.4MEDIUM
CVE-2021-37262
all versions
JFinal_cms 5.1.0 is vulnerable to regex injection that may lead to Denial of Service.
7.5HIGH
CVE-2021-40639
all versions
Improper access control in Jfinal CMS 5.1.0 allows attackers to access sensitive information via /classes/conf/db.properties&confi
7.5HIGH
CVE-2020-19155
<= 4.7.1
Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information and/or execute ar
8.8HIGH
CVE-2020-19154
<= 4.7.1
Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information via the 'FileMana
6.5MEDIUM
CVE-2020-19151
<= 4.7.1
Command Injection in Jfinal CMS v4.7.1 and earlier allows remote attackers to execute arbitrary code by uploading a malicious HTML
8.8HIGH
CVE-2020-19150
<= 4.7.1
Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information or cause a denial
8.1HIGH
CVE-2020-19148
<= 4.7.1
Cross Site Scripting (XSS) in Jfinal CMS v4.7.1 and earlier allows remote attackers to execute arbitrary code via the 'Nickname' p
5.4MEDIUM
CVE-2020-19147
<= 4.7.1
Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive infromation via the 'getFolde
6.5MEDIUM
CVE-2020-19146
<= 4.7.1
Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information via the 'Template
6.5MEDIUM
threatengine.sh