Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Jpress

First CVE: Nov 11, 2018Active for: 8 yearsTotal CVEs: 19
37.1
VTI Score
Medium

Jpress is a content management and blogging platform whose vulnerability footprint, while modest in scope, concentrates in a product deployed across web-hosting environments and personal publishing use cases. The vendor's disclosures skew toward serious outcomes, with an elevated share reaching critical severity, and recur through weakness classes including code injection, cross-site scripting, unrestricted file uploads, and improper handling of alternate data streams—patterns typical of web applications handling user input and file management at scale. Live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
19
Total CVEs
More Total CVEs than 96% of tracked vendors
3.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 95% of tracked vendors
7.3
Avg CVSS Score
Higher Avg CVSS Score than 55% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Jpress over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 11, 2018
7 years ago
Most Recent CVE
Dec 9, 2024
592 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (19 CVEs).

19 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-45807CRITICAL
jpress v4.2.0 is vulnerable to command execution via io.jpress.web.admin._AddonController::doUploadAndInstall.
Jan 13, 20229.833NONO
CVE-2021-46114HIGH
jpress v 4.2.0 is vulnerable to RCE via io.jpress.module.product.ProductNotifyKit#doSendEmail. The admin panel provides a function through which attackers can edit the email templa
Jan 26, 20228.830NONO
CVE-2021-45808HIGH
jpress v4.2.0 allows users to register an account by default. With the account, user can upload arbitrary files to the server.
Jan 19, 20228.830NONO
CVE-2021-45806HIGH
jpress v4.2.0 admin panel provides a function through which attackers can modify the template and inject some malicious code.
Jan 13, 20228.830NONO
CVE-2022-23330HIGH
A remote code execution (RCE) vulnerability in HelloWorldAddonController.java of jpress v4.2.0 allows attackers to execute arbitrary code via a crafted JAR package.
Feb 4, 20228.827NONO
CVE-2024-50919CRITICAL
Jpress until v5.1.1 has arbitrary file uploads on the windows platform, and the construction of non-standard file formats such as .jsp. can lead to arbitrary command execution
Nov 18, 20249.826NONO
CVE-2021-46118HIGH
jpress 4.2.0 is vulnerable to remote code execution via io.jpress.module.article.kit.ArticleNotifyKit#doSendEmail. The admin panel provides a function through which attackers can e
Jan 26, 20227.226NONO
CVE-2021-46116HIGH
jpress 4.2.0 is vulnerable to remote code execution via io.jpress.web.admin._TemplateController#doInstall. The admin panel provides a function through which attackers can install t
Jan 26, 20227.226NONO
CVE-2024-43033HIGH
JPress through 5.1.1 on Windows has an arbitrary file upload vulnerability that could cause arbitrary code execution via ::$DATA to AttachmentController, such as a .jsp::$DATA file
Aug 22, 20248.825NONO
CVE-2021-46117HIGH
jpress 4.2.0 is vulnerable to remote code execution via io.jpress.module.page.PageNotifyKit#doSendEmail. The admin panel provides a function through which attackers can edit the em
Jan 26, 20227.225NONO
View all 19 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products19 CVEs
32%
58%
11%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network19 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low19 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None14 (73.7%)
Unknown0 (0.0%)
Required5 (26.3%)
Privileges Required
Low8 (42.1%)
High6 (31.6%)
None5 (26.3%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (19 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Jpress.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Jpress — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Jpress's Products

View all 2 CNAs →

Top CWEs