Known Vulnerabilities for products from Jizhicms

Listed below are 20 of the newest known vulnerabilities associated with the vendor "Jizhicms".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2026-6978 json Not Provided 2026-04-25 2026-04-27
CVE-2026-3292 json A security vulnerability has been detected in jizhiCMS up to 2.5.6. Affected is the function findAll in the library frphp/lib... Not Provided 2026-02-27 2026-04-29
CVE-2025-50229 json Jizhicms v2.5.4 is vulnerable to SQL injection in the product editing module. Not Provided 2026-04-23 2026-04-27
CVE-2025-50228 json Jizhicms v2.5.4 is vulnerable to Server-Side Request Forgery (SSRF) in User Evaluation, Message, and Comment modules. Not Provided 2026-04-09 2026-04-14
CVE-2025-14013 json A vulnerability was identified in JIZHICMS up to 2.5.5. The impacted element is an unknown function of the file /index.php/ad... Not Provided 2025-12-04 2026-04-29
CVE-2025-14012 json A vulnerability was determined in JIZHICMS up to 2.5.5. The affected element is the function deleteAll/findAll/delete of the ... Not Provided 2025-12-04 2026-04-29
CVE-2025-14011 json A vulnerability was found in JIZHICMS up to 2.5.5. Impacted is the function commentlist of the file /index.php/admins/Comment... Not Provided 2025-12-04 2026-04-29
CVE-2023-50692 json 8.8 - HIGH 2023-12-28 2024-01-04
CVE-2023-43836 json There is a SQL injection vulnerability in the Jizhicms 2.4.9 backend, which users can use to obtain database information 6.5 - MEDIUM 2023-10-02 2023-10-04
CVE-2023-38948 json An arbitrary file download vulnerability in the /c/PluginsController.php component of jizhi CMS 1.9.5 allows attackers to exe... 7.2 - HIGH 2023-08-03 2023-08-08
CVE-2023-31862 json jizhicms v2.4.6 is vulnerable to Cross Site Scripting (XSS). The content of the article published in the front end is only fi... 5.4 - MEDIUM 2023-05-19 2023-05-26
CVE-2023-27235 json An arbitrary file upload vulnerability in the \admin\c\CommonController.php component of Jizhicms v2.4.5 allows attackers to ... 7.2 - HIGH 2023-03-15 2023-03-17
CVE-2023-27234 json A Cross-Site Request Forgery (CSRF) in /Sys/index.html of Jizhicms v2.4.5 allows attackers to arbitrarily make configuration ... 6.5 - MEDIUM 2023-03-15 2023-03-20
CVE-2023-2927 json A vulnerability was found in JIZHICMS 2.4.5. It has been classified as critical. Affected is the function index of the file T... 9.8 - CRITICAL 2023-05-27 2023-11-07
CVE-2022-45278 json Jizhicms v2.3.3 was discovered to contain a SQL injection vulnerability via the /index.php/admins/Fields/get_fields.html comp... 8.8 - HIGH 2022-11-23 2022-11-28
CVE-2022-44140 json Jizhicms v2.3.3 was discovered to contain a SQL injection vulnerability via the /Member/memberedit.html component. 8.8 - HIGH 2022-11-23 2022-11-28
CVE-2022-36578 json jizhicms v2.3.1 has SQL injection in the background. 9.8 - CRITICAL 2022-08-19 2022-08-22
CVE-2022-36577 json An issue was discovered in jizhicms v2.3.1. There is a CSRF vulnerability that can add a admin. 8.8 - HIGH 2022-08-19 2022-08-22
CVE-2022-31393 json Jizhicms v2.2.5 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability via the Index function in app/ad... 9.1 - CRITICAL 2022-06-09 2022-06-15
CVE-2022-31390 json Jizhicms v2.2.5 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability via the Update function in app/a... 9.1 - CRITICAL 2022-06-09 2022-06-15

Known software with vulnerabilities from Jizhicms

Type Vendor Product Version
ApplicationJizhicmsJizhicms1.4