jeecms CVE Vulnerabilities & CVE List (6)

Products (CPE): — CVEs: 6

jeecms vulnerability overview

Aggregates CVE and security vulnerability intelligence across all jeecms-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Common weakness patterns include vendor risk cross-site scripting, vendor risk csrf, and vendor risk ssrf, with potential vendor impact session compromise across vendor surface software deployment use cases.

Vulnerability distribution trend (last 24 months)

Showing 16 of 6 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2020-21729 JEECMS x1.1 contains a stored cross-site scripting (XSS) vulnerability in the component of /member-vipcenter.htm, which allows attackers to execute arbitrary web scripts or HTML via a crafted payload. [email protected] 5.4 0.19% 2021-10-07 2024-11-21
CVE-2020-20799 JeeCMS 1.0.1 contains a stored cross-site scripting (XSS) vulnerability which allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the commentText parameter. [email protected] 5.4 0.26% 2021-09-30 2024-11-21
CVE-2018-20528 JEECMS 9 has SSRF via the ueditor/getRemoteImage.jspx upfile parameter. [email protected] 6.5 0.22% 2018-12-28 2024-11-21
CVE-2018-19545 JEECMS 9.3 has CSRF via the api/admin/role/save URI to add a user. [email protected] 8.8 0.14% 2018-11-26 2024-11-21
CVE-2018-19544 JEECMS 9.3 has CSRF via the api/admin/content/save URI to add news. [email protected] 6.5 0.06% 2018-11-26 2024-11-21
CVE-2018-18952 JEECMS 9.3 has XSS via an index.do#/content/update?type=update URI. [email protected] 4.8 0.17% 2018-11-05 2024-11-21
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence