Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-50228

29
FAUCET Score

Jizhicms v2.5.4 contains a critical Server-Side Request Forgery (SSRF) vulnerability affecting its User Evaluation, Message, and Comment modules, allowing attackers to make unauthorized requests from the affected server. The vulnerability carries a CVSS score of 9.1 (Critical) with a network-based attack vector that requires no authentication or user interaction, making it easily exploitable by remote attackers. The SSRF enables high-impact confidentiality and integrity compromises, as attackers could access internal resources and potentially modify data or systems accessible from the vulnerable server. There is currently no evidence of active exploitation in the wild, with the vulnerability absent from the CISA Known Exploited Vulnerabilities (KEV) catalog and showing minimal community attention. The FAUCET Risk Score of 43.0 and low EPSS score suggest limited real-world exploitation activity to date, though organizations running Jizhicms v2.5.4 should prioritize patching given the critical severity rating.

Impacted Technologies

VendorProductVersion(s)CPE
2.5.4CPE matchmatch criteria
cpe:2.3:a:jizhicms:jizhicms:2.5.4:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

9.1CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
5.2
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.27%
Probability of exploitation in next 30 days
EPSS Percentile
19.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0027 is in the 2nd percentile among its peer group of 36,862 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

github.com / Cherry-toto/jizhicms
Product
github.com / Cherry-toto/jizhicms/issues/104
Issue Tracking
jizhicms.cn
Product