Jocms Project maintains a content management system with a narrow but more prominent than typical deployment footprint, and its disclosed vulnerabilities center on SQL injection flaws within the core product. The profile reflects input-handling and query-construction weaknesses characteristic of web application codebases; current severity, exploitation, and exposure figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Jocms Project over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-36434CRITICAL SQL injection vulnerability in jocms 0.8 allows remote attackers to run arbitrary SQL commands and view sentivie information via jo_json_check function in jocms/apps/mask/inc/getma | Feb 3, 2023 | 9.1 | 29 | NO | NO |
CVE-2021-36433CRITICAL SQL injection vulnerability in jocms 0.8 allows remote attackers to run arbitrary SQL commands and view sentivie information via jo_delete_mask function in jocms/apps/mask/mask.php | Feb 3, 2023 | 9.1 | 28 | NO | NO |
CVE-2021-36431CRITICAL SQL injection vulnerability in jocms 0.8 allows remote attackers to run arbitrary SQL commands and view sentivie information via jo_json_check() function in jocms/apps/mask/inc/mas | Feb 3, 2023 | 9.1 | 28 | NO | NO |
CVE-2021-36432HIGH SQL injection vulnerability in jocms 0.8 allows remote attackers to run arbitrary SQL commands and view sentivie information via jo_set_mask() function in jocms/apps/mask/mask.php. | Feb 3, 2023 | 7.5 | 25 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Jocms Project.
Media articles that mention a CVE ID that affects a product developed by Jocms Project — matched by CVE ID, not by vendor name.