Jspxcms is a web content management system whose vulnerability profile centers on application-layer input handling and access control, with recurring exposures in cross-site scripting, improper access control, server-side request forgery, and sensitive-information disclosure. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Jspxcms over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-20596CRITICAL Jspxcms v9.0.0 allows SSRF. | Dec 30, 2018 | 9.8 | 30 | NO | NO |
CVE-2018-16553HIGH In Jspxcms 9.0.0, a vulnerable URL routing implementation allows remote code execution after logging in as web admin. | Jun 20, 2019 | 7.2 | 24 | NO | NO |
CVE-2024-0721MEDIUM A vulnerability has been found in Jspxcms 10.2.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Survey Label Handler. Th | Jan 19, 2024 | 6.1 | 18 | NO | NO |
CVE-2023-46911MEDIUM There is a Cross Site Scripting (XSS) vulnerability in the choose_style_tree.do interface of Jspxcms v10.2.0 backend. | Nov 1, 2023 | 6.1 | 18 | NO | NO |
CVE-2024-1200MEDIUM A vulnerability was found in Jspxcms 10.2.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /template/1/default/. The manipulation l | Feb 3, 2024 | 6.5 | 17 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Jspxcms.
Media articles that mention a CVE ID that affects a product developed by Jspxcms — matched by CVE ID, not by vendor name.