Jpress is a content management and blogging platform whose vulnerability footprint, while modest in scope, concentrates in a product deployed across web-hosting environments and personal publishing use cases. The vendor's disclosures skew toward serious outcomes, with an elevated share reaching critical severity, and recur through weakness classes including code injection, cross-site scripting, unrestricted file uploads, and improper handling of alternate data streams—patterns typical of web applications handling user input and file management at scale. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Jpress over time
Signals from CVEs in this vendor scope (19 CVEs).
19 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-45807CRITICAL jpress v4.2.0 is vulnerable to command execution via io.jpress.web.admin._AddonController::doUploadAndInstall. | Jan 13, 2022 | 9.8 | 33 | NO | NO |
CVE-2021-46114HIGH jpress v 4.2.0 is vulnerable to RCE via io.jpress.module.product.ProductNotifyKit#doSendEmail. The admin panel provides a function through which attackers can edit the email templa | Jan 26, 2022 | 8.8 | 30 | NO | NO |
CVE-2021-45808HIGH jpress v4.2.0 allows users to register an account by default. With the account, user can upload arbitrary files to the server. | Jan 19, 2022 | 8.8 | 30 | NO | NO |
CVE-2021-45806HIGH jpress v4.2.0 admin panel provides a function through which attackers can modify the template and inject some malicious code. | Jan 13, 2022 | 8.8 | 30 | NO | NO |
CVE-2022-23330HIGH A remote code execution (RCE) vulnerability in HelloWorldAddonController.java of jpress v4.2.0 allows attackers to execute arbitrary code via a crafted JAR package. | Feb 4, 2022 | 8.8 | 27 | NO | NO |
CVE-2024-50919CRITICAL Jpress until v5.1.1 has arbitrary file uploads on the windows platform, and the construction of non-standard file formats such as .jsp. can lead to arbitrary command execution | Nov 18, 2024 | 9.8 | 26 | NO | NO |
CVE-2021-46118HIGH jpress 4.2.0 is vulnerable to remote code execution via io.jpress.module.article.kit.ArticleNotifyKit#doSendEmail. The admin panel provides a function through which attackers can e | Jan 26, 2022 | 7.2 | 26 | NO | NO |
CVE-2021-46116HIGH jpress 4.2.0 is vulnerable to remote code execution via io.jpress.web.admin._TemplateController#doInstall. The admin panel provides a function through which attackers can install t | Jan 26, 2022 | 7.2 | 26 | NO | NO |
CVE-2024-43033HIGH JPress through 5.1.1 on Windows has an arbitrary file upload vulnerability that could cause arbitrary code execution via ::$DATA to AttachmentController, such as a .jsp::$DATA file | Aug 22, 2024 | 8.8 | 25 | NO | NO |
CVE-2021-46117HIGH jpress 4.2.0 is vulnerable to remote code execution via io.jpress.module.page.PageNotifyKit#doSendEmail. The admin panel provides a function through which attackers can edit the em | Jan 26, 2022 | 7.2 | 25 | NO | NO |
Signals from CVEs in this vendor scope (19 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Jpress.
Media articles that mention a CVE ID that affects a product developed by Jpress — matched by CVE ID, not by vendor name.