jeesns CVE Vulnerabilities & Metrics

Focus on jeesns vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About jeesns Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with jeesns. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total jeesns CVEs: 21
Earliest CVE date: 18 Jul 2018, 16:29 UTC
Latest CVE date: 19 Sep 2022, 23:15 UTC

Latest CVE reference: CVE-2022-38550

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 0

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): 0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): 0.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical jeesns CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 3.64

Max CVSS: 6.8

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 16
4.0-6.9 5
7.0-8.9 0
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS jeesns CVEs

These are the five CVEs with the highest CVSS scores for jeesns, sorted by severity first and recency.

All CVEs for jeesns

CVE-2022-38550 jeesns vulnerability CVSS: 0 19 Sep 2022, 23:15 UTC

A stored cross-site scripting (XSS) vulnerability in the /weibo/list component of Jeesns v2.0.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

CVE-2020-19295 jeesns vulnerability CVSS: 4.3 09 Sep 2021, 23:15 UTC

A reflected cross-site scripting (XSS) vulnerability in the /weibo/topic component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML.

CVE-2020-19294 jeesns vulnerability CVSS: 3.5 09 Sep 2021, 23:15 UTC

A stored cross-site scripting (XSS) vulnerability in the /article/comment component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the article comments section.

CVE-2020-19293 jeesns vulnerability CVSS: 3.5 09 Sep 2021, 23:15 UTC

A stored cross-site scripting (XSS) vulnerability in the /article/add component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in a posted article.

CVE-2020-19292 jeesns vulnerability CVSS: 3.5 09 Sep 2021, 23:15 UTC

A stored cross-site scripting (XSS) vulnerability in the /question/ask component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in a posted question.

CVE-2020-19291 jeesns vulnerability CVSS: 3.5 09 Sep 2021, 23:15 UTC

A stored cross-site scripting (XSS) vulnerability in the /weibo/publishdata component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in a posted Weibo.

CVE-2020-19290 jeesns vulnerability CVSS: 3.5 09 Sep 2021, 23:15 UTC

A stored cross-site scripting (XSS) vulnerability in the /weibo/comment component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the Weibo comment section.

CVE-2020-19289 jeesns vulnerability CVSS: 3.5 09 Sep 2021, 23:15 UTC

A stored cross-site scripting (XSS) vulnerability in the /member/picture/album component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the new album tab.

CVE-2020-19288 jeesns vulnerability CVSS: 3.5 09 Sep 2021, 23:15 UTC

A stored cross-site scripting (XSS) vulnerability in the /localhost/u component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in a private message.

CVE-2020-19287 jeesns vulnerability CVSS: 3.5 09 Sep 2021, 23:15 UTC

A stored cross-site scripting (XSS) vulnerability in the /group/post component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the title.

CVE-2020-19286 jeesns vulnerability CVSS: 3.5 09 Sep 2021, 23:15 UTC

A stored cross-site scripting (XSS) vulnerability in the /question/detail component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the source field of the editor.

CVE-2020-19285 jeesns vulnerability CVSS: 3.5 09 Sep 2021, 23:15 UTC

A stored cross-site scripting (XSS) vulnerability in the /group/apply component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the Name text field.

CVE-2020-19284 jeesns vulnerability CVSS: 3.5 09 Sep 2021, 23:15 UTC

A stored cross-site scripting (XSS) vulnerability in the /group/comment component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the group comments text field.

CVE-2020-19283 jeesns vulnerability CVSS: 4.3 09 Sep 2021, 23:15 UTC

A reflected cross-site scripting (XSS) vulnerability in the /newVersion component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML.

CVE-2020-19282 jeesns vulnerability CVSS: 4.3 09 Sep 2021, 23:15 UTC

A reflected cross-site scripting (XSS) vulnerability in Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the system error message's text field.

CVE-2020-19281 jeesns vulnerability CVSS: 3.5 09 Sep 2021, 23:15 UTC

A stored cross-site scripting (XSS) vulnerability in the /manage/loginusername component of Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the username field.

CVE-2020-19280 jeesns vulnerability CVSS: 6.8 09 Sep 2021, 23:15 UTC

Jeesns 1.4.2 contains a cross-site request forgery (CSRF) which allows attackers to escalate privileges and perform sensitive program operations.

CVE-2020-18035 jeesns vulnerability CVSS: 4.3 29 Apr 2021, 23:15 UTC

Cross Site Scripting (XSS) in Jeesns v1.4.2 allows remote attackers to execute arbitrary code by injecting commands into the "CKEditorFuncNum" parameter in the component "CkeditorUploadController.java".

CVE-2018-19178 jeesns vulnerability CVSS: 3.5 11 Nov 2018, 16:29 UTC

In JEESNS 1.3, com/lxinet/jeesns/core/utils/XssHttpServletRequestWrapper.java allows stored XSS via an HTML EMBED element, a different vulnerability than CVE-2018-17886.

CVE-2018-17886 jeesns vulnerability CVSS: 3.5 02 Oct 2018, 18:29 UTC

An issue was discovered in JEESNS 1.3. The XSS filter in com.lxinet.jeesns.core.utils.XssHttpServletRequestWrapper.java could be bypassed, as demonstrated by a <svg/onLoad=confirm substring. NOTE: this vulnerability exists because of an incomplete fix for CVE-2018-12429.

CVE-2018-12429 jeesns vulnerability CVSS: 3.5 18 Jul 2018, 16:29 UTC

JEESNS through 1.2.1 allows XSS attacks by ordinary users who publish articles containing a crafted payload in order to capture an administrator cookie.