Known Vulnerabilities for products from Jizhicms

Listed below are 20 of the newest known vulnerabilities associated with the vendor "Jizhicms".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2025-50228 json Jizhicms v2.5.4 is vulnerable to Server-Side Request Forgery (SSRF) in User Evaluation, Message, and Comment modules. Not Provided 2026-04-09 2026-04-14
CVE-2023-50692 json 8.8 - HIGH 2023-12-28 2024-01-04
CVE-2023-43836 json There is a SQL injection vulnerability in the Jizhicms 2.4.9 backend, which users can use to obtain database information 6.5 - MEDIUM 2023-10-02 2023-10-04
CVE-2023-38948 json An arbitrary file download vulnerability in the /c/PluginsController.php component of jizhi CMS 1.9.5 allows attackers to exe... 7.2 - HIGH 2023-08-03 2023-08-08
CVE-2023-31862 json jizhicms v2.4.6 is vulnerable to Cross Site Scripting (XSS). The content of the article published in the front end is only fi... 5.4 - MEDIUM 2023-05-19 2023-05-26
CVE-2023-27235 json An arbitrary file upload vulnerability in the \admin\c\CommonController.php component of Jizhicms v2.4.5 allows attackers to ... 7.2 - HIGH 2023-03-15 2023-03-17
CVE-2023-27234 json A Cross-Site Request Forgery (CSRF) in /Sys/index.html of Jizhicms v2.4.5 allows attackers to arbitrarily make configuration ... 6.5 - MEDIUM 2023-03-15 2023-03-20
CVE-2023-2927 json A vulnerability was found in JIZHICMS 2.4.5. It has been classified as critical. Affected is the function index of the file T... 9.8 - CRITICAL 2023-05-27 2023-11-07
CVE-2022-45278 json Jizhicms v2.3.3 was discovered to contain a SQL injection vulnerability via the /index.php/admins/Fields/get_fields.html comp... 8.8 - HIGH 2022-11-23 2022-11-28
CVE-2022-44140 json Jizhicms v2.3.3 was discovered to contain a SQL injection vulnerability via the /Member/memberedit.html component. 8.8 - HIGH 2022-11-23 2022-11-28
CVE-2022-36578 json jizhicms v2.3.1 has SQL injection in the background. 9.8 - CRITICAL 2022-08-19 2022-08-22
CVE-2022-36577 json An issue was discovered in jizhicms v2.3.1. There is a CSRF vulnerability that can add a admin. 8.8 - HIGH 2022-08-19 2022-08-22
CVE-2022-31393 json Jizhicms v2.2.5 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability via the Index function in app/ad... 9.1 - CRITICAL 2022-06-09 2022-06-15
CVE-2022-31390 json Jizhicms v2.2.5 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability via the Update function in app/a... 9.1 - CRITICAL 2022-06-09 2022-06-15
CVE-2022-27429 json Jizhicms v1.9.5 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability via /admin.php/Plugins/update.ht... 9.8 - CRITICAL 2022-04-25 2022-05-05
CVE-2021-36484 json ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... 9.8 - CRITICAL 2023-02-03 2023-02-10
CVE-2021-29334 json ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... 8.8 - HIGH 2022-11-23 2022-11-28
CVE-2020-23644 json XSS exists in JIZHICMS 1.7.1 via index.php/Error/index?msg={XSS] to Home/c/ErrorController.php. 6.1 - MEDIUM 2021-01-11 2021-01-13
CVE-2020-23643 json XSS exists in JIZHICMS 1.7.1 via index.php/Wechat/checkWeixin?signature=1&echostr={XSS] to Home/c/WechatController.php. 6.1 - MEDIUM 2021-01-11 2021-01-13
CVE-2020-21483 json An arbitrary file upload vulnerability in Jizhicms v1.5 allows attackers to execute arbitrary code via a crafted .jpg file wh... 7.2 - HIGH 2021-09-15 2021-09-28

Known software with vulnerabilities from Jizhicms

Type Vendor Product Version
ApplicationJizhicmsJizhicms1.4