Home/Product/jizhicms
Product

jizhicms

39 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-50229
all versions
Jizhicms v2.5.4 is vulnerable to SQL injection in the product editing module.
9.8CRITICAL
CVE-2025-50228
all versions
Jizhicms v2.5.4 is vulnerable to Server-Side Request Forgery (SSRF) in User Evaluation, Message, and Comment modules.
9.1CRITICAL
CVE-2026-29840
<= 2.5.6
JiZhiCMS v2.5.6 and before contains a Stored Cross-Site Scripting (XSS) vulnerability in the release function within app/home/c/Us
5.4MEDIUM
CVE-2026-3292
<= 2.5.6
A security vulnerability has been detected in jizhiCMS up to 2.5.6. Affected is the function findAll in the library frphp/lib/Mode
6.3MEDIUM
CVE-2025-70397
all versions
jizhicms 2.5.6 is vulnerable to SQL Injection in Article/deleteAll and Extmolds/deleteAll via the data parameter.
7.2HIGH
CVE-2020-37117
all versions
jizhiCMS 1.6.7 contains a file download vulnerability in the admin plugins update endpoint that allows authenticated administrator
8.8HIGH
CVE-2025-14013
<= 2.5.5
A vulnerability was identified in JIZHICMS up to 2.5.5. The impacted element is an unknown function of the file /index.php/admins/
2.4LOW
CVE-2025-14012
<= 2.5.5
A vulnerability was determined in JIZHICMS up to 2.5.5. The affected element is the function deleteAll/findAll/delete of the file
4.7MEDIUM
CVE-2025-14011
<= 2.5.5
A vulnerability was found in JIZHICMS up to 2.5.5. Impacted is the function commentlist of the file /index.php/admins/Comment/addc
4.7MEDIUM
CVE-2025-2639
<= 1.7
A vulnerability has been found in JIZHICMS up to 1.7.0 and classified as problematic. This vulnerability affects unknown code of t
4.3MEDIUM
CVE-2025-2638
<= 1.7
A vulnerability, which was classified as problematic, was found in JIZHICMS up to 1.7.0. This affects an unknown part of the file
4.3MEDIUM
CVE-2025-2637
<= 1.7
A vulnerability, which was classified as problematic, has been found in JIZHICMS up to 1.7.0. Affected by this issue is some unkno
4.3MEDIUM
CVE-2025-25785
all versions
JizhiCMS v2.5.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the component \c\PluginsController.php. This vu
9.1CRITICAL
CVE-2025-25784
all versions
An arbitrary file upload vulnerability in the component \c\TemplateController.php of Jizhicms v2.5.4 allows attackers to execute a
9.8CRITICAL
CVE-2024-34255
all versions
jizhicms v2.5.1 contains a Cross-Site Scripting(XSS) vulnerability in the message function.
6.1MEDIUM
CVE-2024-33338
all versions
Cross Site Scripting vulnerability in jizhicms v.2.5.4 allows a remote attacker to obtain sensitive information via a crafted arti
7.3HIGH
CVE-2024-32161
all versions
jizhiCMS 2.5 suffers from a File upload vulnerability.
9.8CRITICAL
CVE-2023-51154
all versions
Jizhicms v2.5 was discovered to contain an arbitrary file download vulnerability via the component /admin/c/PluginsController.php.
9.8CRITICAL
CVE-2023-50692
all versions
File Upload vulnerability in JIZHICMS v.2.5, allows remote attacker to execute arbitrary code via a crafted file uploaded and down
8.8HIGH
CVE-2023-43836
all versions
There is a SQL injection vulnerability in the Jizhicms 2.4.9 backend, which users can use to obtain database information
6.5MEDIUM
CVE-2023-38948
all versions
An arbitrary file download vulnerability in the /c/PluginsController.php component of jizhi CMS 1.9.5 allows attackers to execute
7.2HIGH
CVE-2023-2927
all versions
A vulnerability was found in JIZHICMS 2.4.5. It has been classified as critical. Affected is the function index of the file Templa
6.3MEDIUM
CVE-2023-31862
all versions
jizhicms v2.4.6 is vulnerable to Cross Site Scripting (XSS). The content of the article published in the front end is only filtere
5.4MEDIUM
CVE-2023-27235
all versions
An arbitrary file upload vulnerability in the \admin\c\CommonController.php component of Jizhicms v2.4.5 allows attackers to execu
7.2HIGH
CVE-2023-27234
all versions
A Cross-Site Request Forgery (CSRF) in /Sys/index.html of Jizhicms v2.4.5 allows attackers to arbitrarily make configuration chang
6.5MEDIUM
CVE-2021-36484
all versions
SQL injection vulnerability in JIZHICMS 1.9.5 allows attackers to run arbitrary SQL commands via add or edit article page.
9.8CRITICAL
CVE-2022-45278
all versions
Jizhicms v2.3.3 was discovered to contain a SQL injection vulnerability via the /index.php/admins/Fields/get_fields.html component
8.8HIGH
CVE-2022-44140
all versions
Jizhicms v2.3.3 was discovered to contain a SQL injection vulnerability via the /Member/memberedit.html component.
8.8HIGH
CVE-2021-29334
all versions
An issue was discovered in JIZHI CMS 1.9.4. There is a CSRF vulnerability that can add an admin account via index, /admin.php/Admi
8.8HIGH
CVE-2022-36578
all versions
jizhicms v2.3.1 has SQL injection in the background.
9.8CRITICAL
CVE-2022-36577
all versions
An issue was discovered in jizhicms v2.3.1. There is a CSRF vulnerability that can add a admin.
8.8HIGH
CVE-2022-31393
all versions
Jizhicms v2.2.5 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability via the Index function in app/admin/c
9.1CRITICAL
CVE-2022-31390
all versions
Jizhicms v2.2.5 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability via the Update function in app/admin/
9.1CRITICAL
CVE-2022-27429
all versions
Jizhicms v1.9.5 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability via /admin.php/Plugins/update.html.
9.8CRITICAL
CVE-2020-21228
all versions
JIZHICMS 1.5.1 contains a cross-site scripting (XSS) vulnerability in the component /user/release.html, which allows attackers to
6.1MEDIUM
CVE-2020-21483
all versions
An arbitrary file upload vulnerability in Jizhicms v1.5 allows attackers to execute arbitrary code via a crafted .jpg file which i
7.2HIGH
CVE-2020-23644
all versions
XSS exists in JIZHICMS 1.7.1 via index.php/Error/index?msg={XSS] to Home/c/ErrorController.php.
6.1MEDIUM
CVE-2020-23643
all versions
XSS exists in JIZHICMS 1.7.1 via index.php/Wechat/checkWeixin?signature=1&echostr={XSS] to Home/c/WechatController.php.
6.1MEDIUM
CVE-2019-17593
all versions
JIZHICMS 1.5.1 allows admin.php/Admin/adminadd.html CSRF to add an administrator.
8.8HIGH
threatengine.sh