njtech CVE Vulnerabilities & Metrics

Focus on njtech vulnerabilities and metrics.

Last updated: 16 Jan 2026, 23:25 UTC

About njtech Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with njtech. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total njtech CVEs: 9
Earliest CVE date: 01 Jun 2018, 17:29 UTC
Latest CVE date: 29 Dec 2025, 12:15 UTC

Latest CVE reference: CVE-2025-15187

Rolling Stats

30-day Count (Rolling): 1
365-day Count (Rolling): 3

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0.0%
Year Variation (Calendar): 200.0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): 200.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical njtech CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 4.29

Max CVSS: 6.8

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 3
4.0-6.9 6
7.0-8.9 0
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS njtech CVEs

These are the five CVEs with the highest CVSS scores for njtech, sorted by severity first and recency.

All CVEs for njtech

CVE-2025-15187 njtech vulnerability CVSS: 4.7 29 Dec 2025, 12:15 UTC

A vulnerability was found in GreenCMS up to 2.3. This affects an unknown part of the file /DataController.class.php of the component File Handler. Performing manipulation of the argument sqlFiles/zipFiles results in path traversal. The attack can be initiated remotely. The exploit has been made public and could be used. This vulnerability only affects products that are no longer supported by the maintainer.

CVE-2025-14244 njtech vulnerability CVSS: 3.3 08 Dec 2025, 12:16 UTC

A flaw has been found in GreenCMS 2.3.0603. Affected by this issue is some unknown functionality of the file /Admin/Controller/CustomController.class.php of the component Menu Management Page. This manipulation of the argument Link causes cross site scripting. The attack may be initiated remotely. The exploit has been published and may be used. This vulnerability only affects products that are no longer supported by the maintainer.

CVE-2025-9415 njtech vulnerability CVSS: 6.5 25 Aug 2025, 19:15 UTC

A vulnerability was identified in GreenCMS up to 2.3.0603. This affects an unknown part of the file /index.php?m=admin&c=media&a=fileconnect. The manipulation of the argument upload[] leads to unrestricted upload. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. This vulnerability only affects products that are no longer supported by the maintainer.

CVE-2024-22570 njtech vulnerability CVSS: 0 29 Jan 2024, 20:15 UTC

A stored cross-site scripting (XSS) vulnerability in /install.php?m=install&c=index&a=step3 of GreenCMS v2.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

CVE-2020-21366 njtech vulnerability CVSS: 0 20 Jun 2023, 15:15 UTC

Cross Site Request Forgery vulnerability in GreenCMS v.2.3 allows an attacker to gain privileges via the adduser function of index.php.

CVE-2022-28918 njtech vulnerability CVSS: 5.5 26 Apr 2022, 21:15 UTC

GreenCMS v2.3.0603 was discovered to contain an arbitrary file deletion vulnerability via /index.php?m=admin&c=custom&a=plugindelhandle&plugin_name=.

CVE-2018-12604 njtech vulnerability CVSS: 5.0 20 Jun 2018, 19:29 UTC

GreenCMS 2.3.0603 allows remote attackers to obtain sensitive information via a direct request for Data/Log/year_month_day.log.

CVE-2018-11671 njtech vulnerability CVSS: 6.8 01 Jun 2018, 17:29 UTC

An issue was discovered in GreenCMS v2.3.0603. There is a CSRF vulnerability that can add an admin account via index.php?m=admin&c=access&a=adduserhandle.

CVE-2018-11670 njtech vulnerability CVSS: 6.8 01 Jun 2018, 17:29 UTC

An issue was discovered in GreenCMS v2.3.0603. There is a CSRF vulnerability that allows attackers to execute arbitrary PHP code via the content parameter to index.php?m=admin&c=media&a=fileconnect.