Jrecms maintains a focused content-management platform centered on its Spring Boot–based CMS product, which presents a web-application attack surface. The recurring vulnerability pattern reflects classic input-handling weaknesses, including cross-site scripting, SQL injection, and improper input neutralization across form and query processing. Current vulnerability counts, severity distribution, and exploitation status are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Jrecms over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-43192HIGH SQL injection can exist in a newly created part of the SpringbootCMS 1.0 background, and the parameters submitted by users are not filtered. As a result, special characters in para | Sep 27, 2023 | 8.8 | 24 | NO | NO |
CVE-2022-4282HIGH A vulnerability was found in SpringBootCMS and classified as critical. Affected by this issue is some unknown functionality of the component Template Management. The manipulation l | Dec 5, 2022 | 7.2 | 24 | NO | NO |
CVE-2023-43191MEDIUM SpringbootCMS 1.0 foreground message can be embedded malicious code saved in the database. When users browse the comments, these malicious codes embedded in the HTML will be execut | Sep 27, 2023 | 5.4 | 18 | NO | NO |
CVE-2024-6539MEDIUM A vulnerability classified as problematic has been found in heyewei SpringBootCMS up to 2024-05-28. Affected is an unknown function of the file /guestbook of the component Guestboo | Jul 7, 2024 | 4.8 | 17 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Jrecms.
Media articles that mention a CVE ID that affects a product developed by Jrecms — matched by CVE ID, not by vendor name.