Skip to main content

Vendor/product archive

ujcms / jspxcms CVEs

Beta · best-effort

6 CVEs tagged to ujcms / jspxcms1 Critical, 0 High, 2 Medium, 3 Low, 0 Unrated.

CVE-2025-25772

Published Feb 21, 2025

A Cross-Site Request Forgery (CSRF) in the component /back/UserController.java of Jspxcms v9.0 to v9.5 allows attackers to arbitrarily add Administrator accounts via a crafted req…

CVSS 5.1 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-1257

Published Feb 6, 2024

A vulnerability was found in Jspxcms 10.2.0. It has been classified as problematic. Affected is an unknown function of the file /ext/collect/find_text.do. The manipulation leads t…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-1256

Published Feb 6, 2024

A vulnerability was found in Jspxcms 10.2.0 and classified as problematic. This issue affects some unknown processing of the file /ext/collect/filter_text.do. The manipulation lea…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-0599

Published Jan 16, 2024

A vulnerability was found in Jspxcms 10.2.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file src\main\java\com\jspxcms\…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-28090

Published May 4, 2022

Jspxcms v10.2.0 allows attackers to execute a Server-Side Request Forgery (SSRF) via /cmscp/ext/collect/fetch_url.do?url=.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-23329

Published Feb 4, 2022

A vulnerability in ${"freemarker.template.utility.Execute"?new() of UJCMS Jspxcms v10.2.0 allows attackers to execute arbitrary commands via uploading malicious files.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-6 of 6 CVEsPage 1 of 1