Jfinalcms Project develops a web content management system whose vulnerability exposure, while concentrated in a single product, positions it among the more prominent CMS platforms tracked in vulnerability databases. The durable profile reflects the application's web-facing role and recurs through classic input-handling and session-management weakness classes—cross-site request forgery, cross-site scripting, SQL injection, and path traversal—alongside cleartext storage of sensitive data, all of which are endemic to web applications lacking defense-in-depth input validation and access controls. A meaningful share of the vendor's disclosures reach serious severity, consistent with the direct exploitability of these weaknesses in production environments. Defenders deploying this CMS should prioritize patching, inventory instances with internet exposure, and enforce input validation and session-protection controls at the application tier; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Jfinalcms Project over time
Signals from CVEs in this vendor scope (39 CVEs).
39 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-41599MEDIUM An issue in the component /common/DownController.java of JFinalCMS v5.0.0 allows attackers to execute a directory traversal. | Sep 19, 2023 | 5.3 | 30 | NO | YES |
CVE-2022-27341CRITICAL JFinalCMS v2.0 was discovered to contain a SQL injection vulnerability via the Article Management function. | Apr 22, 2022 | 9.8 | 30 | NO | NO |
CVE-2024-24029CRITICAL JFinalCMS 5.0.0 is vulnerable to SQL injection via /admin/content/data. | Feb 2, 2024 | 9.8 | 26 | NO | NO |
CVE-2024-40322HIGH An issue was discovered in JFinalCMS v.5.0.0. There is a SQL injection vulnerablity via /admin/div_data/data | Jul 16, 2024 | 8.8 | 24 | NO | NO |
CVE-2023-49447HIGH JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/nav/update. | Dec 5, 2023 | 8.8 | 23 | NO | NO |
CVE-2023-49396HIGH JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/category/save. | Dec 5, 2023 | 8.8 | 23 | NO | NO |
CVE-2023-49382HIGH JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/div/delete. | Dec 5, 2023 | 8.8 | 23 | NO | NO |
CVE-2023-49378HIGH JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/form/save. | Dec 5, 2023 | 8.8 | 23 | NO | NO |
CVE-2023-49375HIGH JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/friend_link/update. | Dec 5, 2023 | 8.8 | 23 | NO | NO |
CVE-2023-49373HIGH JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/slide/delete. | Dec 5, 2023 | 8.8 | 23 | NO | NO |
Signals from CVEs in this vendor scope (39 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Jfinalcms Project.
Media articles that mention a CVE ID that affects a product developed by Jfinalcms Project — matched by CVE ID, not by vendor name.