Products: 2
    Vulnerabilities: 8
    Known Exploited: 0
    1
    Critical Level Threats
    0
    High Level Threats
    3
    Medium Level Threats
    4
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-2200

    heyewei JFinalCMS API Endpoint save cross site scripting

    Last Modified: Apr 18, 2026
    Published: Feb 09, 2026

    CVE-2024-57665

    JFinalCMS 1.0 is vulnerable to SQL Injection in rc/main/java/com/cms/entity/Content.java. The cause of the vulnerability is that the title parameter is controllable and is concatenated directly into filterSql without filtering.

    Last Modified: May 23, 2025
    Published: Jan 29, 2025

    CVE-2024-8782

    JFinalCMS edit delete path traversal

    Last Modified: Sep 19, 2024
    Published: Sep 13, 2024

    CVE-2024-8706

    JFinalCMS com.cms.util.TemplateUtils update path traversal

    Last Modified: Jun 05, 2025
    Published: Sep 11, 2024

    CVE-2024-8694

    JFinalCMS com.cms.controller.admin.TemplateController update path traversal

    Last Modified: Jun 05, 2025
    Published: Sep 11, 2024
    Items Per Page