Jfinalcms
Vendor:
First CVE: Apr 22, 2022 · Active for 4 years
39
Total CVEs
More Total CVEs than 97% of tracked products
13.0
Avg CVEs / Year
Higher CVE frequency than 97% of tracked products
7.5
Avg CVSS
Higher Avg CVSS than 59% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Jfinalcms over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 22, 2022
4 years ago
Most Recent CVE
Jul 16, 2024
738 days ago
CVE Severity & Scoring
Jfinalcms39 CVEs
38%
56%
All CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network39 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low39 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None6 (15.4%)
Unknown0 (0.0%)
Required33 (84.6%)
Privileges Required
Low12 (30.8%)
High0 (0.0%)
None27 (69.2%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (39 CVEs).
39 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-41599MEDIUM An issue in the component /common/DownController.java of JFinalCMS v5.0.0 allows attackers to execute a directory traversal. | Sep 19, 2023 | 5.3 | 30 | NO | YES |
CVE-2022-27341CRITICAL JFinalCMS v2.0 was discovered to contain a SQL injection vulnerability via the Article Management function. | Apr 22, 2022 | 9.8 | 30 | NO | NO |
CVE-2024-24029CRITICAL JFinalCMS 5.0.0 is vulnerable to SQL injection via /admin/content/data. | Feb 2, 2024 | 9.8 | 26 | NO | NO |
CVE-2024-40322HIGH An issue was discovered in JFinalCMS v.5.0.0. There is a SQL injection vulnerablity via /admin/div_data/data | Jul 16, 2024 | 8.8 | 24 | NO | NO |
CVE-2023-49447HIGH JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/nav/update. | Dec 5, 2023 | 8.8 | 23 | NO | NO |
CVE-2023-49396HIGH JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/category/save. | Dec 5, 2023 | 8.8 | 23 | NO | NO |
CVE-2023-49382HIGH JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/div/delete. | Dec 5, 2023 | 8.8 | 23 | NO | NO |
CVE-2023-49378HIGH JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/form/save. | Dec 5, 2023 | 8.8 | 23 | NO | NO |
CVE-2023-49375HIGH JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/friend_link/update. | Dec 5, 2023 | 8.8 | 23 | NO | NO |
CVE-2023-49373HIGH JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/slide/delete. | Dec 5, 2023 | 8.8 | 23 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (39 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
2.6% of CVEs· 96th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (39 CVEs).
Media Mentions
Signals from CVEs in this product scope (39 CVEs).
Top CNAs Publishing CVEs For Jfinalcms
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 5.0.0 | 37 | 7.4 | 0.7% | 0 | 1 |
| 5.0 | 1 | 8.8 | 0.4% | 0 | 0 |
| 2.0 | 1 | 9.8 | 1.2% | 0 | 0 |