Vulnerabilities > Jizhicms > High

DATE CVE VULNERABILITY TITLE RISK
2023-12-28 CVE-2023-50692 Unrestricted Upload of File with Dangerous Type vulnerability in Jizhicms 2.5
File Upload vulnerability in JIZHICMS v.2.5, allows remote attacker to execute arbitrary code via a crafted file uploaded and downloaded to the download_url parameter in the app/admin/exts/ directory.
network
low complexity
jizhicms CWE-434
8.8
2023-08-03 CVE-2023-38948 Files or Directories Accessible to External Parties vulnerability in Jizhicms 1.9.5
An arbitrary file download vulnerability in the /c/PluginsController.php component of jizhi CMS 1.9.5 allows attackers to execute arbitrary code via downloading a crafted plugin.
network
low complexity
jizhicms CWE-552
7.2
2023-03-15 CVE-2023-27235 Unrestricted Upload of File with Dangerous Type vulnerability in Jizhicms 2.4.5
An arbitrary file upload vulnerability in the \admin\c\CommonController.php component of Jizhicms v2.4.5 allows attackers to execute arbitrary code via a crafted phtml file.
network
low complexity
jizhicms CWE-434
7.2
2022-11-23 CVE-2022-45278 SQL Injection vulnerability in Jizhicms 2.3.3
Jizhicms v2.3.3 was discovered to contain a SQL injection vulnerability via the /index.php/admins/Fields/get_fields.html component.
network
low complexity
jizhicms CWE-89
8.8
2022-11-23 CVE-2021-29334 Cross-Site Request Forgery (CSRF) vulnerability in Jizhicms 1.9.4
An issue was discovered in JIZHI CMS 1.9.4.
network
low complexity
jizhicms CWE-352
8.8
2022-11-23 CVE-2022-44140 SQL Injection vulnerability in Jizhicms 2.3.3
Jizhicms v2.3.3 was discovered to contain a SQL injection vulnerability via the /Member/memberedit.html component.
network
low complexity
jizhicms CWE-89
8.8
2022-04-25 CVE-2022-27429 Server-Side Request Forgery (SSRF) vulnerability in Jizhicms 1.9.5
Jizhicms v1.9.5 was discovered to contain a Server-Side Request Forgery (SSRF) vulnerability via /admin.php/Plugins/update.html.
network
low complexity
jizhicms CWE-918
7.5