com.jfinal:jfinal
Maven36 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting com.jfinal:jfinalpage 1 of 1
- CVE-2019-17352HIGHCVSS 7.5EG 7.5✓ Fixed in 4.52019-10-08
vulnerable: 1.4 ... 4.4 (23 versions)
In JFinal cos before 2019-08-13, as used in JFinal 4.4, there is a vulnerability that can bypass the isSafeFile() function: one can upload any type of file. For example, a .jsp file may be stored and almost immediately deleted, but this de…
- CVE-2021-31635CRITICALCVSS 9.8EG 9.82023-06-26
vulnerable: 1.4 ... 4.9.08 (36 versions)
Server-Side Template Injection (SSTI) vulnerability in jFinal v.4.9.08 allows a remote attacker to execute arbitrary code via the template function.
- CVE-2021-31649CRITICALCVSS 9.8EG 9.82021-06-24
vulnerable: 1.4 ... 4.9.08 (36 versions)
In applications using jfinal 4.9.08 and below, there is a deserialization vulnerability when using redis,may be vulnerable to remote code execute
- CVE-2021-33348MEDIUMCVSS 6.1EG 6.1✓ Fixed in 4.9.112021-06-24
vulnerable: 1.4 ... 4.9.10 (38 versions)
An issue was discovered in JFinal framework v4.9.10 and below. The "set" method of the "Controller" class of jfinal framework is not strictly filtered, which will lead to XSS vulnerabilities in some cases.
- CVE-2022-33113MEDIUMCVSS 5.4EG 5.42022-06-23
vulnerable: 1.4 ... 5.0.8 (60 versions)
Jfinal CMS v5.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the keyword text field under the publish blog module.
- CVE-2023-49372HIGHCVSS 8.8EG 8.82023-12-05
vulnerable: 1.4 ... 5.0.0 (52 versions)
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/slide/save.
- CVE-2023-49373HIGHCVSS 8.8EG 8.82023-12-05
vulnerable: 1.4 ... 5.0.0 (52 versions)
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/slide/delete.
- CVE-2023-49374HIGHCVSS 8.8EG 8.82023-12-05
vulnerable: 1.4 ... 5.0.0 (52 versions)
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/slide/update.
- CVE-2023-49375HIGHCVSS 8.8EG 8.82023-12-05
vulnerable: 1.4 ... 5.0.0 (52 versions)
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/friend_link/update.
- CVE-2023-49376HIGHCVSS 8.8EG 8.82023-12-05
vulnerable: 1.4 ... 5.0.0 (52 versions)
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/tag/delete.
- CVE-2023-49377HIGHCVSS 8.8EG 8.82023-12-05
vulnerable: 1.4 ... 5.0.0 (52 versions)
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/tag/update.
- CVE-2023-49378HIGHCVSS 8.8EG 8.82023-12-05
vulnerable: 1.4 ... 5.0.0 (52 versions)
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/form/save.
- CVE-2023-49379HIGHCVSS 8.8EG 8.82023-12-05
vulnerable: 1.4 ... 5.0.0 (52 versions)
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the component /admin/friend_link/save.
- CVE-2023-49380HIGHCVSS 8.8EG 8.82023-12-05
vulnerable: 1.4 ... 5.0.0 (52 versions)
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/friend_link/delete.
- CVE-2023-49381HIGHCVSS 8.8EG 8.82023-12-05
vulnerable: 1.4 ... 5.0.0 (52 versions)
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/div/update.
- CVE-2023-49382HIGHCVSS 8.8EG 8.82023-12-05
vulnerable: 1.4 ... 5.0.0 (52 versions)
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/div/delete.
- CVE-2023-49383HIGHCVSS 8.8EG 8.82023-12-05
vulnerable: 1.4 ... 5.0.0 (52 versions)
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/tag/save.
- CVE-2023-49395HIGHCVSS 8.8EG 8.82023-12-05
vulnerable: 1.4 ... 5.0.0 (52 versions)
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/category/update.
- CVE-2023-49396HIGHCVSS 8.8EG 8.82023-12-05
vulnerable: 1.4 ... 5.0.0 (52 versions)
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/category/save.
- CVE-2023-49397HIGHCVSS 8.8EG 8.82023-12-05
vulnerable: 1.4 ... 5.0.0 (52 versions)
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/category/updateStatus.
- CVE-2023-49398HIGHCVSS 8.8EG 8.82023-12-05
vulnerable: 1.4 ... 5.0.0 (52 versions)
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/category/delete.
- CVE-2023-49446HIGHCVSS 8.8EG 8.82023-12-05
vulnerable: 1.4 ... 5.0.0 (52 versions)
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/nav/save.
- CVE-2023-49447HIGHCVSS 8.8EG 8.82023-12-05
vulnerable: 1.4 ... 5.0.0 (52 versions)
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/nav/update.
- CVE-2023-49448HIGHCVSS 8.8EG 8.82023-12-05
vulnerable: 1.4 ... 5.0.0 (52 versions)
JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via admin/nav/delete.
- CVE-2023-49485MEDIUMCVSS 5.4EG 5.42023-12-08
vulnerable: 1.4 ... 5.0.0 (52 versions)
JFinalCMS v5.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the column management department.
- CVE-2023-49486MEDIUMCVSS 5.4EG 5.42023-12-08
vulnerable: 1.4 ... 5.0.0 (52 versions)
JFinalCMS v5.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the model management department.
- CVE-2023-49487MEDIUMCVSS 5.4EG 5.42023-12-08
vulnerable: 1.4 ... 5.0.0 (52 versions)
JFinalCMS v5.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the navigation management department.
- CVE-2023-50100MEDIUMCVSS 5.4EG 5.42023-12-14
vulnerable: 1.4 ... 5.0.0 (52 versions)
JFinalcms 5.0.0 is vulnerable to Cross Site Scripting (XSS) via carousel image editing.
- CVE-2023-50101MEDIUMCVSS 5.4EG 5.42023-12-14
vulnerable: 1.4 ... 5.0.0 (52 versions)
JFinalcms 5.0.0 is vulnerable to Cross Site Scripting (XSS) via Label management editing.
- CVE-2023-50102MEDIUMCVSS 5.4EG 5.42023-12-14
vulnerable: 1.4 ... 5.0.0 (52 versions)
JFinalcms 5.0.0 is vulnerable to Cross Site Scripting (XSS).
- CVE-2023-50137MEDIUMCVSS 5.4EG 5.42023-12-14
vulnerable: 1.4 ... 5.0.0 (52 versions)
JFinalcms 5.0.0 is vulnerable to Cross Site Scripting (XSS) in the site management office.
- CVE-2023-50449HIGHCVSS 7.5EG 7.52023-12-10
vulnerable: 1.4 ... 5.0.0 (52 versions)
JFinalCMS 5.0.0 could allow a remote attacker to read files via ../ Directory Traversal in the /common/down/file fileKey parameter.
- CVE-2024-22492MEDIUMCVSS 5.4EG 5.42024-01-12
vulnerable: 1.4 ... 5.0.0 (52 versions)
A stored XSS vulnerability exists in JFinalcms 5.0.0 via the /gusetbook/save contact parameter, which allows remote attackers to inject arbitrary web script or HTML.
- CVE-2024-22493MEDIUMCVSS 5.4EG 5.42024-01-12
vulnerable: 1.4 ... 5.0.0 (52 versions)
A stored XSS vulnerability exists in JFinalcms 5.0.0 via the /gusetbook/save content parameter, which allows remote attackers to inject arbitrary web script or HTML.
- CVE-2024-22496MEDIUMCVSS 6.1EG 6.12024-01-23
vulnerable: 1.4 ... 5.0.0 (52 versions)
Cross Site Scripting (XSS) vulnerability in JFinalcms 5.0.0 allows attackers to run arbitrary code via the /admin/login username parameter.
- CVE-2024-22497MEDIUMCVSS 6.1EG 6.12024-01-23
vulnerable: 1.4 ... 5.0.0 (52 versions)
Cross Site Scripting (XSS) vulnerability in /admin/login password parameter in JFinalcms 5.0.0 allows attackers to run arbitrary code via crafted URL.
Check whether com.jfinal:jfinal is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for com.jfinal:jfinal CVEs against the assets you own.
Start Free Scan →