JflyfoxCVEs & Vulnerabilities

51 CVEs affecting Jflyfox products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.

Most Affected Products

jfinal cms 51
CVE-2025-6105HIGH

A vulnerability has been found in jflyfox jfinal_cms 5.0.1 and classified as problematic. This vulnerability affects unknown code of the file HOME.java. The manipulation of the argument Logout leads to cross-site request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

16 Jun 2025
8.8
CVSS
CVE-2024-53477CRITICAL

JFinal CMS 5.1.0 is vulnerable to Command Execution via unauthorized execution of deserialization in the file ApiForm.java

3 Dec 2024
9.8
CVSS
CVE-2023-47503CRITICAL

An issue in jflyfox jfinalCMS v.5.1.0 allows a remote attacker to execute arbitrary code via a crafted script to the login.jsp component in the template management module.

28 Nov 2023
9.8
CVSS
CVE-2023-34645HIGH

jfinal CMS 5.1.0 has an arbitrary file read vulnerability.

16 Jun 2023
7.5
CVSS
CVE-2023-30349CRITICAL

JFinal CMS v5.1.0 was discovered to contain a remote code execution (RCE) vulnerability via the ActionEnter function.

27 Apr 2023
9.8
CVSS
CVE-2023-24747MEDIUM

Jfinal CMS v5.1 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /system/dict/list.

5 Apr 2023
5.4
CVSS
CVE-2023-22975MEDIUM

A cross-site scripting (XSS) vulnerability in JFinal CMS v5.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the email parameter under /front/person/profile.html.

3 Feb 2023
6.1
CVSS
CVE-2022-37202HIGH

JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/advicefeedback/list

26 Oct 2022
8.8
CVSS
CVE-2022-37208HIGH

JFinal CMS 5.1.0 is vulnerable to SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection.

13 Oct 2022
8.8
CVSS
CVE-2022-37209HIGH

JFinal CMS 5.1.0 is affected by: SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection.

28 Sep 2022
8.8
CVSS
CVE-2022-37205HIGH

JFinal CMS 5.1.0 is affected by: SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection.

20 Sep 2022
8.8
CVSS
CVE-2022-37204CRITICAL

Final CMS 5.1.0 is vulnerable to SQL Injection.

20 Sep 2022
9.8
CVSS
CVE-2022-37203CRITICAL

JFinal CMS 5.1.0 is vulnerable to SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection.

19 Sep 2022
9.8
CVSS
CVE-2022-37201HIGH

JFinal CMS 5.1.0 is vulnerable to SQL Injection.

15 Sep 2022
8.8
CVSS
CVE-2022-37207HIGH

JFinal CMS 5.1.0 is affected by: SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection

15 Sep 2022
8.8
CVSS
CVE-2022-38286HIGH

JFinal CMS 5.1.0 is vulnerable to SQL Injection via /system/role/list.

9 Sep 2022
7.2
CVSS
CVE-2022-38285HIGH

JFinal CMS 5.1.0 is vulnerable to SQL Injection via /system/menu/list.

9 Sep 2022
7.2
CVSS
CVE-2022-38284HIGH

JFinal CMS 5.1.0 is vulnerable to SQL Injection via /system/department/list.

9 Sep 2022
7.2
CVSS
CVE-2022-38283HIGH

JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/video/list.

9 Sep 2022
7.2
CVSS
CVE-2022-38282HIGH

JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/videoalbum/list.

9 Sep 2022
7.2
CVSS
CVE-2022-38281HIGH

JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/site/list.

9 Sep 2022
7.2
CVSS
CVE-2022-38280HIGH

JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/image/list.

9 Sep 2022
7.2
CVSS
CVE-2022-38279HIGH

JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/imagealbum/list.

9 Sep 2022
7.2
CVSS
CVE-2022-38278HIGH

JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/friendlylink/list.

9 Sep 2022
7.2
CVSS
CVE-2022-38277HIGH

JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/folderrollpicture/list.

9 Sep 2022
7.2
CVSS
CVE-2022-38276HIGH

JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/foldernotice/list.

9 Sep 2022
7.2
CVSS
CVE-2022-38275HIGH

JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/contact/list.

9 Sep 2022
7.2
CVSS
CVE-2022-38274HIGH

JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/comment/list.

9 Sep 2022
7.2
CVSS
CVE-2022-38273HIGH

JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/article/list_approve.

9 Sep 2022
7.2
CVSS
CVE-2022-38272HIGH

JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/article/list.

9 Sep 2022
7.2
CVSS
CVE-2022-36527MEDIUM

Jfinal CMS v5.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the post title text field under the publish blog module.

25 Aug 2022
5.4
CVSS
CVE-2022-37223CRITICAL

JFinal CMS 5.1.0 is vulnerable to SQL Injection via /jfinal_cms/system/role/list.

23 Aug 2022
9.8
CVSS
CVE-2022-37199CRITICAL

JFinal CMS 5.1.0 is vulnerable to SQL Injection via /jfinal_cms/system/user/list.

23 Aug 2022
9.8
CVSS
CVE-2022-34928HIGH

JFinal CMS v5.1.0 was discovered to contain a SQL injection vulnerability via /system/user.

3 Aug 2022
8.8
CVSS
CVE-2022-33114HIGH

Jfinal CMS v5.1.0 was discovered to contain a SQL injection vulnerability via the attrVal parameter at /jfinal_cms/system/dict/list.

23 Jun 2022
7.2
CVSS
CVE-2022-33113MEDIUM

Jfinal CMS v5.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the keyword text field under the publish blog module.

23 Jun 2022
5.4
CVSS
CVE-2022-29648MEDIUM

A cross-site scripting (XSS) vulnerability in Jfinal CMS v5.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted X-Forwarded-For request.

2 Jun 2022
5.4
CVSS
CVE-2022-30500CRITICAL

Jfinal cms 5.1.0 is vulnerable to SQL Injection.

26 May 2022
9.8
CVSS
CVE-2021-42242CRITICAL

A command execution vulnerability exists in jfinal_cms 5.0.1 via com.jflyfox.component.controller.Ueditor.

5 May 2022
9.8
CVSS
CVE-2022-28505HIGH

Jfinal_cms 5.1.0 is vulnerable to SQL Injection via com.jflyfox.system.log.LogController.java.

3 May 2022
7.2
CVSS
CVE-2022-27111MEDIUM

Jfinal_CMS 5.1.0 allows attackers to use the feedback function to send malicious XSS code to the administrator backend and execute it.

11 Apr 2022
5.4
CVSS
CVE-2021-46087MEDIUM

In jfinal_cms >= 5.1 0, there is a storage XSS vulnerability in the background system of CMS. Because developers do not filter the parameters submitted by the user input form, any user with background permission can affect the system security by entering malicious code.

25 Jan 2022
5.4
CVSS
CVE-2021-37262HIGH

JFinal_cms 5.1.0 is vulnerable to regex injection that may lead to Denial of Service.

16 Dec 2021
7.5
CVSS
CVE-2021-40639HIGH

Improper access control in Jfinal CMS 5.1.0 allows attackers to access sensitive information via /classes/conf/db.properties&config=filemanager.config.js.

16 Sep 2021
7.5
CVSS
CVE-2020-19155HIGH

Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information and/or execute arbitrary code via the 'FileManager.rename()' function in the component 'modules/filemanager/FileManagerController.java'.

15 Sep 2021
8.8
CVSS
CVE-2020-19154MEDIUM

Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information via the 'FileManager.editFile()' function in the component 'modules/filemanager/FileManagerController.java'.

15 Sep 2021
6.5
CVSS
CVE-2020-19151HIGH

Command Injection in Jfinal CMS v4.7.1 and earlier allows remote attackers to execute arbitrary code by uploading a malicious HTML template file via the component 'jfinal_cms/admin/filemanager/list'.

15 Sep 2021
8.8
CVSS
CVE-2020-19150HIGH

Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information or cause a denial of service via the 'FileManager.delete()' function in the component 'modules/filemanager/FileManagerController.java'.

15 Sep 2021
8.1
CVSS
← PrevPage 1 / 2Next →