📦 Jfinalcms

by Heyewei

🔍 What is Jfinalcms?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-8782

MEDIUM CVSS 6.3 Sep 13, 2024

This critical vulnerability in JFinalCMS allows remote attackers to perform path traversal attacks via the 'name' parameter in the delete function of the admin template editor. Attackers can delete ar...

CVE-2026-2200

LOW CVSS 2.4 Feb 9, 2026

This vulnerability allows remote attackers to inject malicious scripts via the /admin/admin/save API endpoint in heyewei JFinalCMS 5.0.0. The cross-site scripting (XSS) attack can be executed remotely...