Jflyfox maintains a narrowly scoped portfolio centered on the JFinal CMS web application platform, which despite limited product breadth has attracted a moderate volume of vulnerability disclosures and sits among the more prominent CMS targets tracked in the landscape. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and concentrate in classic web-application weakness classes: SQL injection, cross-site scripting, path traversal, and resource-exposure flaws that reflect the platform's role as a direct handler of user input and file-system operations. The recurring pattern across JFinal CMS disclosures underscores the structural risks inherent in content-management systems that bridge database, template, and file-access layers, and defenders should treat this vendor's security bulletins as having high-severity implications for deployments. Current exploitation activity, severity breakdown, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Jflyfox over time
Signals from CVEs in this vendor scope (51 CVEs).
51 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-42242CRITICAL A command execution vulnerability exists in jfinal_cms 5.0.1 via com.jflyfox.component.controller.Ueditor. | May 5, 2022 | 9.8 | 32 | NO | NO |
CVE-2022-37199CRITICAL JFinal CMS 5.1.0 is vulnerable to SQL Injection via /jfinal_cms/system/user/list. | Aug 23, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-37204CRITICAL Final CMS 5.1.0 is vulnerable to SQL Injection. | Sep 20, 2022 | 9.8 | 30 | NO | NO |
CVE-2022-37223CRITICAL JFinal CMS 5.1.0 is vulnerable to SQL Injection via /jfinal_cms/system/role/list. | Aug 23, 2022 | 9.8 | 30 | NO | NO |
CVE-2022-30500CRITICAL Jfinal cms 5.1.0 is vulnerable to SQL Injection. | May 26, 2022 | 9.8 | 30 | NO | NO |
CVE-2020-19155HIGH Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information and/or execute arbitrary code via the 'FileManager.rename()' functi | Sep 15, 2021 | 8.8 | 30 | NO | NO |
CVE-2023-47503CRITICAL An issue in jflyfox jfinalCMS v.5.1.0 allows a remote attacker to execute arbitrary code via a crafted script to the login.jsp component in the template management module. | Nov 28, 2023 | 9.8 | 29 | NO | NO |
CVE-2023-30349CRITICAL JFinal CMS v5.1.0 was discovered to contain a remote code execution (RCE) vulnerability via the ActionEnter function. | Apr 27, 2023 | 9.8 | 29 | NO | NO |
CVE-2022-37208HIGH JFinal CMS 5.1.0 is vulnerable to SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting | Oct 13, 2022 | 8.8 | 28 | NO | NO |
CVE-2022-37209HIGH JFinal CMS 5.1.0 is affected by: SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting | Sep 27, 2022 | 8.8 | 28 | NO | NO |
Signals from CVEs in this vendor scope (51 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Jflyfox.
Media articles that mention a CVE ID that affects a product developed by Jflyfox — matched by CVE ID, not by vendor name.