Jizhicms is a content-management system that, despite a narrow product scope, occupies a notable position in the vulnerability landscape and skews strongly toward critical-severity outcomes. The recurring weakness classes affecting the platform center on web-application input handling and server-side behavior: SQL injection, cross-site scripting, server-side request forgery, improper file-upload validation, and cross-site request forgery reflect common parsing and authorization gaps in CMS implementations. Defenders deploying this platform should prioritize systematic input validation, access control enforcement, and file-handling controls; current severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Jizhicms over time
Signals from CVEs in this vendor scope (39 CVEs).
39 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-50229CRITICAL Jizhicms v2.5.4 is vulnerable to SQL injection in the product editing module. | Apr 23, 2026 | 9.8 | 30 | NO | NO |
CVE-2023-2927CRITICAL A vulnerability was found in JIZHICMS 2.4.5. It has been classified as critical. Affected is the function index of the file TemplateController.php. The manipulation of the argument | May 27, 2023 | 9.8 | 30 | NO | NO |
CVE-2022-36578CRITICAL jizhicms v2.3.1 has SQL injection in the background. | Aug 19, 2022 | 9.8 | 30 | NO | NO |
CVE-2022-27429CRITICAL Jizhicms v1.9.5 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability via /admin.php/Plugins/update.html. | Apr 25, 2022 | 9.8 | 30 | NO | NO |
CVE-2025-50228CRITICAL Jizhicms v2.5.4 is vulnerable to Server-Side Request Forgery (SSRF) in User Evaluation, Message, and Comment modules. | Apr 9, 2026 | 9.1 | 29 | NO | NO |
CVE-2021-36484CRITICAL SQL injection vulnerability in JIZHICMS 1.9.5 allows attackers to run arbitrary SQL commands via add or edit article page. | Feb 3, 2023 | 9.8 | 29 | NO | NO |
CVE-2026-3292HIGH A security vulnerability has been detected in jizhiCMS up to 2.5.6. Affected is the function findAll in the library frphp/lib/Model.php of the component Batch Interface. The manipu | Feb 27, 2026 | 8.8 | 28 | NO | NO |
CVE-2020-37117HIGH jizhiCMS 1.6.7 contains a file download vulnerability in the admin plugins update endpoint that allows authenticated administrators to download arbitrary files. Attackers can explo | Feb 5, 2026 | 8.8 | 28 | NO | NO |
CVE-2025-25784CRITICAL An arbitrary file upload vulnerability in the component \c\TemplateController.php of Jizhicms v2.5.4 allows attackers to execute arbitrary code via uploading a crafted Zip file. | Feb 26, 2025 | 9.8 | 28 | NO | NO |
CVE-2024-32161CRITICAL jizhiCMS 2.5 suffers from a File upload vulnerability. | Apr 17, 2024 | 9.8 | 28 | NO | NO |
Signals from CVEs in this vendor scope (39 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Jizhicms.
Media articles that mention a CVE ID that affects a product developed by Jizhicms — matched by CVE ID, not by vendor name.