
yukino-hiki/CVE
Releases0
CVE History
| CVE | Published | CVSS v3 | CVSS v2 |
|---|---|---|---|
| 6.1 MEDIUM | — | ||
Cross Site Scripting vulnerability in Jfinalcms v.5.0.0 allows a remote attacker to execute arbitrary code via a crafted script to the friendship link component. | |||
| 5.4 MEDIUM | — | ||
Cross Site Scripting (XSS) vulnerability in JFinalcms 5.0.0 allows attackers to run arbitrary code via the name field when creating a new custom table. | |||
| 5.4 MEDIUM | — | ||
JFinalcms 5.0.0 is vulnerable to Cross Site Scripting (XSS) in the site management office. | |||