Jportal operates a web portal and server product that, despite narrow scope, ranks among more prominent vendors in the vulnerability landscape. The disclosure pattern centers on input-handling issues—notably SQL injection—characteristic of web-facing portal software, and while vulnerability counts remain modest, public exploit code acquisition is a durable tendency for this vendor's flaws. Defenders should prioritize patches for internet-exposed Jportal instances; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Jportal over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2004-2036HIGH SQL injection vulnerability in the art_print function in print.inc.php in unknown versions of jPortal before 2.3.1 allows remote attackers to inject arbitrary SQL commands via the | May 28, 2004 | 7.5 | 29 | NO | YES |
CVE-2008-6451HIGH SQL injection vulnerability in humor.php in jPORTAL 2 allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: this might overlap CVE-2004-2036 or CVE- | Mar 13, 2009 | 7.5 | 28 | NO | YES |
CVE-2007-5973HIGH SQL injection vulnerability in articles.php in JPortal 2.3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the topic parameter. | Nov 15, 2007 | 7.5 | 28 | NO | YES |
CVE-2007-5974HIGH SQL injection vulnerability in mailer.php in JPortal 2 allows remote attackers to execute arbitrary SQL commands via the to parameter. | Nov 15, 2007 | 7.5 | 28 | NO | YES |
CVE-2007-5912HIGH SQL injection vulnerability in mailer.php in jPORTAL 2 allows remote attackers to execute arbitrary SQL commands via the to parameter. | Nov 10, 2007 | 7.5 | 28 | NO | YES |
CVE-2005-3509HIGH Multiple SQL injection vulnerabilities in JPortal allow remote attackers to execute arbitrary SQL commands via (1) banner.php or the id parameter to (2) print.php, (3) comment.php, | Nov 6, 2005 | 7.5 | 28 | NO | YES |
CVE-2005-3052HIGH SQL injection vulnerability in module/down.inc.php in jportal 2.3.1 allows remote attackers to execute arbitrary SQL commands via the search field to download.php. | Sep 24, 2005 | 7.5 | 28 | NO | YES |
CVE-2005-1071HIGH SQL injection vulnerability in banner.inc.php in JPortal Web Portal 2.3.1 allows remote attackers to execute arbitrary SQL commands via the haslo parameter. | Apr 12, 2005 | 7.5 | 28 | NO | YES |
CVE-2007-0912HIGH Cross-Site Request Forgery (CSRF) vulnerability in admin/admin.adm.php in Jportal 2.3.1, and possibly earlier, allows remote attackers to perform privileged actions as administrato | Feb 13, 2007 | 9.3 | 23 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Jportal.
Media articles that mention a CVE ID that affects a product developed by Jportal — matched by CVE ID, not by vendor name.