JFinal is a lightweight Java web framework focused on rapid application development, with a narrow but significant exposure surface centered on its core framework product. The observed vulnerability classes—untrusted deserialization, code injection, cross-site scripting, and unsafe file uploads—reflect common web-application input handling and object-handling risks endemic to Java web frameworks. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Jfinal over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-31649CRITICAL In applications using jfinal 4.9.08 and below, there is a deserialization vulnerability when using redis,may be vulnerable to remote code execute | Jun 24, 2021 | 9.8 | 29 | NO | NO |
CVE-2021-31635CRITICAL Server-Side Template Injection (SSTI) vulnerability in jFinal v.4.9.08 allows a remote attacker to execute arbitrary code via the template function. | Jun 26, 2023 | 9.8 | 28 | NO | NO |
CVE-2019-17352HIGH In JFinal cos before 2019-08-13, as used in JFinal 4.4, there is a vulnerability that can bypass the isSafeFile() function: one can upload any type of file. For example, a .jsp fil | Oct 8, 2019 | 7.5 | 24 | NO | NO |
CVE-2021-33348MEDIUM An issue was discovered in JFinal framework v4.9.10 and below. The "set" method of the "Controller" class of jfinal framework is not strictly filtered, which will lead to XSS vulne | Jun 24, 2021 | 6.1 | 20 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Jfinal.
Media articles that mention a CVE ID that affects a product developed by Jfinal — matched by CVE ID, not by vendor name.