Jaf Cms
Vendor:
First CVE: Dec 31, 2004 · Active for 21 years
9
Total CVEs
More Total CVEs than 86% of tracked products
2.3
Avg CVEs / Year
Higher CVE frequency than 73% of tracked products
6.4
Avg CVSS
Higher Avg CVSS than 27% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Jaf Cms over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 31, 2004
21 years ago
Most Recent CVE
Nov 27, 2007
6,814 days ago
CVE Severity & Scoring
Jaf Cms9 CVEs
67%
33%
All CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown9 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown9 (100.0%)
User Interaction
None0 (0.0%)
Unknown9 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown9 (100.0%)
Top CVEs
Signals from CVEs in this product scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-7128HIGH PHP remote file inclusion vulnerability in forum/forum.php JAF CMS 4.0 RC1 allows remote attackers to execute arbitrary PHP code via a URL in the website parameter. | Mar 6, 2007 | 7.5 | 31 | NO | YES |
CVE-2006-7127MEDIUM Multiple PHP remote file inclusion vulnerabilities in JAF CMS 4.0 and 4.0 RC2 allow remote attackers to execute arbitrary PHP code via a URL in the main_dir parameter to (1) forum/ | Mar 6, 2007 | 6.8 | 28 | NO | YES |
CVE-2006-5131HIGH module/shout/jafshout.php (aka the shoutbox) in ph03y3nk just another flat file (JAF) CMS 4.0 RC1 allows remote attackers to execute arbitrary code within sections bounded by "<?ph | Oct 3, 2006 | 7.5 | 20 | NO | NO |
CVE-2004-1505HIGH Directory traversal vulnerability in index.php in Just Another Flat file (JAF) CMS 3.0RC allows remote attackers to read arbitrary files and possibly execute PHP code via a .. (dot | Dec 31, 2004 | 7.5 | 20 | NO | NO |
CVE-2004-1504MEDIUM The displaycontent function in config.php for Just Another Flat file (JAF) CMS 3.0RC allows remote attackers to gain sensitive information via a blank show parameter, which reveals | Dec 31, 2004 | 5.0 | 19 | NO | NO |
CVE-2006-5129MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in ph03y3nk just another flat file (JAF) CMS 4.0 RC1 allow remote attackers to inject arbitrary web script or HTML via (1) the m | Oct 3, 2006 | 6.8 | 18 | NO | NO |
CVE-2006-5130MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in ph03y3nk just another flat file (JAF) CMS 4.0 RC1 allow remote attackers to inject arbitrary web script or HTML via the (1) n | Oct 3, 2006 | 6.8 | 18 | NO | NO |
CVE-2005-2053MEDIUM Just another flat file (JAF) CMS before 3.0 Final allows remote attackers to obtain sensitive information via (1) an * (asterisk) in the id parameter, (2) a blank id parameter, or | Jun 28, 2005 | 5.0 | 15 | NO | NO |
CVE-2007-6142MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in ph03y3nk just another flat file (JAF) CMS 4.0 RC2 allow remote attackers to inject arbitrary web script or HTML via the (1) s | Nov 27, 2007 | 4.3 | 14 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (9 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
22.2% of CVEs· 90th percentile
Social Chatter
Signals from CVEs in this product scope (9 CVEs).
Media Mentions
Signals from CVEs in this product scope (9 CVEs).
Top CNAs Publishing CVEs For Jaf Cms
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 4.0_rc2 | 1 | 4.3 | 1.0% | 0 | 0 |
| 4.0 | 5 | 7.0 | 3.9% | 0 | 2 |
| 3.0 | 3 | 5.5 | 1.7% | 0 | 0 |
| 2.5 | 1 | 5.0 | 1.7% | 0 | 0 |
| 2.1.0 | 1 | 5.0 | 1.7% | 0 | 0 |
| 2.0.5 | 1 | 5.0 | 1.7% | 0 | 0 |
| 2.0 | 1 | 5.0 | 1.7% | 0 | 0 |
| 1.5 | 1 | 5.0 | 1.7% | 0 | 0 |
| 1.0 | 1 | 5.0 | 1.7% | 0 | 0 |