jflyfox CVE Vulnerabilities & Metrics

Focus on jflyfox vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About jflyfox Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with jflyfox. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total jflyfox CVEs: 49
Earliest CVE date: 15 Sep 2021, 14:15 UTC
Latest CVE date: 28 Nov 2023, 02:15 UTC

Latest CVE reference: CVE-2023-47503

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 0

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): -100.0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): -100.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical jflyfox CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 1.76

Max CVSS: 7.5

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 37
4.0-6.9 10
7.0-8.9 2
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS jflyfox CVEs

These are the five CVEs with the highest CVSS scores for jflyfox, sorted by severity first and recency.

All CVEs for jflyfox

CVE-2023-47503 jflyfox vulnerability CVSS: 0 28 Nov 2023, 02:15 UTC

An issue in jflyfox jfinalCMS v.5.1.0 allows a remote attacker to execute arbitrary code via a crafted script to the login.jsp component in the template management module.

CVE-2023-34645 jflyfox vulnerability CVSS: 0 16 Jun 2023, 18:15 UTC

jfinal CMS 5.1.0 has an arbitrary file read vulnerability.

CVE-2023-30349 jflyfox vulnerability CVSS: 0 27 Apr 2023, 14:15 UTC

JFinal CMS v5.1.0 was discovered to contain a remote code execution (RCE) vulnerability via the ActionEnter function.

CVE-2023-24747 jflyfox vulnerability CVSS: 0 05 Apr 2023, 20:15 UTC

Jfinal CMS v5.1 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /system/dict/list.

CVE-2023-22975 jflyfox vulnerability CVSS: 0 03 Feb 2023, 17:15 UTC

A cross-site scripting (XSS) vulnerability in JFinal CMS v5.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the email parameter under /front/person/profile.html.

CVE-2022-37202 jflyfox vulnerability CVSS: 0 26 Oct 2022, 18:15 UTC

JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/advicefeedback/list

CVE-2022-37208 jflyfox vulnerability CVSS: 0 13 Oct 2022, 12:15 UTC

JFinal CMS 5.1.0 is vulnerable to SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection.

CVE-2022-37209 jflyfox vulnerability CVSS: 0 27 Sep 2022, 23:15 UTC

JFinal CMS 5.1.0 is affected by: SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection.

CVE-2022-37205 jflyfox vulnerability CVSS: 0 20 Sep 2022, 18:15 UTC

JFinal CMS 5.1.0 is affected by: SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection.

CVE-2022-37204 jflyfox vulnerability CVSS: 0 20 Sep 2022, 17:15 UTC

Final CMS 5.1.0 is vulnerable to SQL Injection.

CVE-2022-37203 jflyfox vulnerability CVSS: 0 19 Sep 2022, 16:15 UTC

JFinal CMS 5.1.0 is vulnerable to SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection.

CVE-2022-37201 jflyfox vulnerability CVSS: 0 15 Sep 2022, 16:15 UTC

JFinal CMS 5.1.0 is vulnerable to SQL Injection.

CVE-2022-37207 jflyfox vulnerability CVSS: 0 15 Sep 2022, 15:15 UTC

JFinal CMS 5.1.0 is affected by: SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection

CVE-2022-38286 jflyfox vulnerability CVSS: 0 09 Sep 2022, 14:15 UTC

JFinal CMS 5.1.0 is vulnerable to SQL Injection via /system/role/list.

CVE-2022-38285 jflyfox vulnerability CVSS: 0 09 Sep 2022, 14:15 UTC

JFinal CMS 5.1.0 is vulnerable to SQL Injection via /system/menu/list.

CVE-2022-38284 jflyfox vulnerability CVSS: 0 09 Sep 2022, 14:15 UTC

JFinal CMS 5.1.0 is vulnerable to SQL Injection via /system/department/list.

CVE-2022-38283 jflyfox vulnerability CVSS: 0 09 Sep 2022, 14:15 UTC

JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/video/list.

CVE-2022-38282 jflyfox vulnerability CVSS: 0 09 Sep 2022, 14:15 UTC

JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/videoalbum/list.

CVE-2022-38281 jflyfox vulnerability CVSS: 0 09 Sep 2022, 14:15 UTC

JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/site/list.

CVE-2022-38280 jflyfox vulnerability CVSS: 0 09 Sep 2022, 14:15 UTC

JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/image/list.

CVE-2022-38279 jflyfox vulnerability CVSS: 0 09 Sep 2022, 14:15 UTC

JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/imagealbum/list.

CVE-2022-38278 jflyfox vulnerability CVSS: 0 09 Sep 2022, 14:15 UTC

JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/friendlylink/list.

CVE-2022-38277 jflyfox vulnerability CVSS: 0 09 Sep 2022, 14:15 UTC

JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/folderrollpicture/list.

CVE-2022-38276 jflyfox vulnerability CVSS: 0 09 Sep 2022, 14:15 UTC

JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/foldernotice/list.

CVE-2022-38275 jflyfox vulnerability CVSS: 0 09 Sep 2022, 14:15 UTC

JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/contact/list.

CVE-2022-38274 jflyfox vulnerability CVSS: 0 09 Sep 2022, 14:15 UTC

JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/comment/list.

CVE-2022-38273 jflyfox vulnerability CVSS: 0 09 Sep 2022, 14:15 UTC

JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/article/list_approve.

CVE-2022-38272 jflyfox vulnerability CVSS: 0 09 Sep 2022, 14:15 UTC

JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/article/list.

CVE-2022-36527 jflyfox vulnerability CVSS: 0 25 Aug 2022, 19:15 UTC

Jfinal CMS v5.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the post title text field under the publish blog module.

CVE-2022-37223 jflyfox vulnerability CVSS: 0 23 Aug 2022, 14:15 UTC

JFinal CMS 5.1.0 is vulnerable to SQL Injection via /jfinal_cms/system/role/list.

CVE-2022-37199 jflyfox vulnerability CVSS: 0 23 Aug 2022, 13:15 UTC

JFinal CMS 5.1.0 is vulnerable to SQL Injection via /jfinal_cms/system/user/list.

CVE-2022-34928 jflyfox vulnerability CVSS: 0 03 Aug 2022, 01:15 UTC

JFinal CMS v5.1.0 was discovered to contain a SQL injection vulnerability via /system/user.

CVE-2022-33114 jflyfox vulnerability CVSS: 6.5 23 Jun 2022, 17:15 UTC

Jfinal CMS v5.1.0 was discovered to contain a SQL injection vulnerability via the attrVal parameter at /jfinal_cms/system/dict/list.

CVE-2022-33113 jflyfox vulnerability CVSS: 3.5 23 Jun 2022, 17:15 UTC

Jfinal CMS v5.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the keyword text field under the publish blog module.

CVE-2022-29648 jflyfox vulnerability CVSS: 3.5 02 Jun 2022, 14:15 UTC

A cross-site scripting (XSS) vulnerability in Jfinal CMS v5.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted X-Forwarded-For request.

CVE-2022-30500 jflyfox vulnerability CVSS: 7.5 26 May 2022, 16:15 UTC

Jfinal cms 5.1.0 is vulnerable to SQL Injection.

CVE-2021-42242 jflyfox vulnerability CVSS: 7.5 05 May 2022, 13:15 UTC

A command execution vulnerability exists in jfinal_cms 5.0.1 via com.jflyfox.component.controller.Ueditor.

CVE-2022-28505 jflyfox vulnerability CVSS: 6.5 03 May 2022, 17:15 UTC

Jfinal_cms 5.1.0 is vulnerable to SQL Injection via com.jflyfox.system.log.LogController.java.

CVE-2022-27111 jflyfox vulnerability CVSS: 3.5 11 Apr 2022, 15:15 UTC

Jfinal_CMS 5.1.0 allows attackers to use the feedback function to send malicious XSS code to the administrator backend and execute it.

CVE-2021-46087 jflyfox vulnerability CVSS: 3.5 25 Jan 2022, 16:15 UTC

In jfinal_cms >= 5.1 0, there is a storage XSS vulnerability in the background system of CMS. Because developers do not filter the parameters submitted by the user input form, any user with background permission can affect the system security by entering malicious code.

CVE-2021-37262 jflyfox vulnerability CVSS: 5.0 16 Dec 2021, 19:15 UTC

JFinal_cms 5.1.0 is vulnerable to regex injection that may lead to Denial of Service.

CVE-2021-40639 jflyfox vulnerability CVSS: 5.0 15 Sep 2021, 22:15 UTC

Improper access control in Jfinal CMS 5.1.0 allows attackers to access sensitive information via /classes/conf/db.properties&config=filemanager.config.js.

CVE-2020-19155 jflyfox vulnerability CVSS: 6.5 15 Sep 2021, 14:15 UTC

Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information and/or execute arbitrary code via the 'FileManager.rename()' function in the component 'modules/filemanager/FileManagerController.java'.

CVE-2020-19154 jflyfox vulnerability CVSS: 4.0 15 Sep 2021, 14:15 UTC

Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information via the 'FileManager.editFile()' function in the component 'modules/filemanager/FileManagerController.java'.

CVE-2020-19151 jflyfox vulnerability CVSS: 6.5 15 Sep 2021, 14:15 UTC

Command Injection in Jfinal CMS v4.7.1 and earlier allows remote attackers to execute arbitrary code by uploading a malicious HTML template file via the component 'jfinal_cms/admin/filemanager/list'.

CVE-2020-19150 jflyfox vulnerability CVSS: 5.5 15 Sep 2021, 14:15 UTC

Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information or cause a denial of service via the 'FileManager.delete()' function in the component 'modules/filemanager/FileManagerController.java'.

CVE-2020-19148 jflyfox vulnerability CVSS: 3.5 15 Sep 2021, 14:15 UTC

Cross Site Scripting (XSS) in Jfinal CMS v4.7.1 and earlier allows remote attackers to execute arbitrary code via the 'Nickname' parameter in the component '/jfinal_cms/front/person/profile.html'.

CVE-2020-19147 jflyfox vulnerability CVSS: 4.0 15 Sep 2021, 14:15 UTC

Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive infromation via the 'getFolder()' function in the component '/modules/filemanager/FileManager.java'.

CVE-2020-19146 jflyfox vulnerability CVSS: 4.0 15 Sep 2021, 14:15 UTC

Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information via the 'TemplatePath' parameter in the component 'jfinal_cms/admin/folder/list'.