Known Vulnerabilities for products from Jizhicms
Listed below are 20 of the newest known vulnerabilities associated with the vendor "Jizhicms".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2025-50228 json | Jizhicms v2.5.4 is vulnerable to Server-Side Request Forgery (SSRF) in User Evaluation, Message, and Comment modules. | Not Provided | 2026-04-09 | 2026-04-14 |
| CVE-2023-50692 json | 8.8 - HIGH | 2023-12-28 | 2024-01-04 | |
| CVE-2023-43836 json | There is a SQL injection vulnerability in the Jizhicms 2.4.9 backend, which users can use to obtain database information | 6.5 - MEDIUM | 2023-10-02 | 2023-10-04 |
| CVE-2023-38948 json | An arbitrary file download vulnerability in the /c/PluginsController.php component of jizhi CMS 1.9.5 allows attackers to exe... | 7.2 - HIGH | 2023-08-03 | 2023-08-08 |
| CVE-2023-31862 json | jizhicms v2.4.6 is vulnerable to Cross Site Scripting (XSS). The content of the article published in the front end is only fi... | 5.4 - MEDIUM | 2023-05-19 | 2023-05-26 |
| CVE-2023-27235 json | An arbitrary file upload vulnerability in the \admin\c\CommonController.php component of Jizhicms v2.4.5 allows attackers to ... | 7.2 - HIGH | 2023-03-15 | 2023-03-17 |
| CVE-2023-27234 json | A Cross-Site Request Forgery (CSRF) in /Sys/index.html of Jizhicms v2.4.5 allows attackers to arbitrarily make configuration ... | 6.5 - MEDIUM | 2023-03-15 | 2023-03-20 |
| CVE-2023-2927 json | A vulnerability was found in JIZHICMS 2.4.5. It has been classified as critical. Affected is the function index of the file T... | 9.8 - CRITICAL | 2023-05-27 | 2023-11-07 |
| CVE-2022-45278 json | Jizhicms v2.3.3 was discovered to contain a SQL injection vulnerability via the /index.php/admins/Fields/get_fields.html comp... | 8.8 - HIGH | 2022-11-23 | 2022-11-28 |
| CVE-2022-44140 json | Jizhicms v2.3.3 was discovered to contain a SQL injection vulnerability via the /Member/memberedit.html component. | 8.8 - HIGH | 2022-11-23 | 2022-11-28 |
| CVE-2022-36578 json | jizhicms v2.3.1 has SQL injection in the background. | 9.8 - CRITICAL | 2022-08-19 | 2022-08-22 |
| CVE-2022-36577 json | An issue was discovered in jizhicms v2.3.1. There is a CSRF vulnerability that can add a admin. | 8.8 - HIGH | 2022-08-19 | 2022-08-22 |
| CVE-2022-31393 json | Jizhicms v2.2.5 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability via the Index function in app/ad... | 9.1 - CRITICAL | 2022-06-09 | 2022-06-15 |
| CVE-2022-31390 json | Jizhicms v2.2.5 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability via the Update function in app/a... | 9.1 - CRITICAL | 2022-06-09 | 2022-06-15 |
| CVE-2022-27429 json | Jizhicms v1.9.5 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability via /admin.php/Plugins/update.ht... | 9.8 - CRITICAL | 2022-04-25 | 2022-05-05 |
| CVE-2021-36484 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 9.8 - CRITICAL | 2023-02-03 | 2023-02-10 |
| CVE-2021-29334 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 8.8 - HIGH | 2022-11-23 | 2022-11-28 |
| CVE-2020-23644 json | XSS exists in JIZHICMS 1.7.1 via index.php/Error/index?msg={XSS] to Home/c/ErrorController.php. | 6.1 - MEDIUM | 2021-01-11 | 2021-01-13 |
| CVE-2020-23643 json | XSS exists in JIZHICMS 1.7.1 via index.php/Wechat/checkWeixin?signature=1&echostr={XSS] to Home/c/WechatController.php. | 6.1 - MEDIUM | 2021-01-11 | 2021-01-13 |
| CVE-2020-21483 json | An arbitrary file upload vulnerability in Jizhicms v1.5 allows attackers to execute arbitrary code via a crafted .jpg file wh... | 7.2 - HIGH | 2021-09-15 | 2021-09-28 |
Known software with vulnerabilities from Jizhicms
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Jizhicms | Jizhicms | 1.4 |