Known Vulnerabilities for products from Jeecms
Listed below are 6 of the newest known vulnerabilities associated with the vendor "Jeecms".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2020-21729 json | JEECMS x1.1 contains a stored cross-site scripting (XSS) vulnerability in the component of /member-vipcenter.htm, which allow... | 5.4 - MEDIUM | 2021-10-07 | 2021-10-14 |
| CVE-2020-20799 json | JeeCMS 1.0.1 contains a stored cross-site scripting (XSS) vulnerability which allows attackers to execute arbitrary web scrip... | 5.4 - MEDIUM | 2021-09-30 | 2021-10-04 |
| CVE-2018-20528 json | JEECMS 9 has SSRF via the ueditor/getRemoteImage.jspx upfile parameter. | 6.5 - MEDIUM | 2018-12-28 | 2019-03-12 |
| CVE-2018-19545 json | JEECMS 9.3 has CSRF via the api/admin/role/save URI to add a user. | 8.8 - HIGH | 2018-11-26 | 2018-12-19 |
| CVE-2018-19544 json | JEECMS 9.3 has CSRF via the api/admin/content/save URI to add news. | 6.5 - MEDIUM | 2018-11-26 | 2018-12-19 |
| CVE-2018-18952 json | JEECMS 9.3 has XSS via an index.do#/content/update?type=update URI. | 4.8 - MEDIUM | 2018-11-05 | 2018-12-10 |
Known software with vulnerabilities from Jeecms
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Jeecms | Jeecms | 9 |