jpress kayıtları
jpress üreticisine ait 19 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 3
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-94 Improper Control of Generation of Code ('Code Injection')6
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')5
- CWE-434 Unrestricted Upload of File with Dangerous Type3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-69 Improper Handling of Windows ::DATA Alternate Data Stream1
- CWE-918 Server-Side Request Forgery (SSRF)1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
19 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2021-45807İstismar yok | jpress v4.2.0 is vulnerable to command execution via io.jpress.web.admin._AddonController::doUploadAndInstall.jpress · jpress | Kritik9,8 | — | %2,1 | 13 Oca 2022 |
39İzleyin | CVE-2024-50919İstismar yok | Jpress until v5.1.1 has arbitrary file uploads on the windows platform, and the construction of non-standard file formats such as .jsp.jpress · jpress · CWE-94 | Kritik9,8 | — | %1,2 | 18 Kas 2024 |
36İzleyin | CVE-2022-23330İstismar yok | A remote code execution (RCE) vulnerability in HelloWorldAddonController.java of jpress v4.2.0 allows attackers to execute arbitrary code vijpress · jpress | Yüksek8,8 | — | %1,9 | 4 Şub 2022 |
35İzleyin | CVE-2021-45806İstismar yok | jpress v4.2.0 admin panel provides a function through which attackers can modify the template and inject some malicious code.jpress · jpress · CWE-94 | Yüksek8,8 | — | %1,4 | 13 Oca 2022 |
35İzleyin | CVE-2021-46114İstismar yok | jpress v 4.2.0 is vulnerable to RCE via io.jpress.module.product.ProductNotifyKit#doSendEmail.jpress · jpress · CWE-94 | Yüksek8,8 | — | %1,3 | 26 Oca 2022 |
35İzleyin | CVE-2021-45808İstismar yok | jpress v4.2.0 allows users to register an account by default.jpress · jpress · CWE-434 | Yüksek8,8 | — | %1,3 | 19 Oca 2022 |
35İzleyin | CVE-2024-43033İstismar yok | JPress through 5.1.1 on Windows has an arbitrary file upload vulnerability that could cause arbitrary code execution via ::$DATA to Attachmejpress · jpress · CWE-69 | Yüksek8,8 | — | %1,0 | 21 Ağu 2024 |
30İzleyin | CVE-2024-32358İstismar yok | An issue in Jpress v.5.1.0 allows a remote attacker to execute arbitrary code via a crafted script to the custom plug-in module function, a jpress · jpress · CWE-94 | Yüksek7,5 | — | %0,7 | 25 Nis 2024 |
30İzleyin | CVE-2024-46468İstismar yok | A Server-Side Request Forgery (SSRF) vulnerability exists in the jpress <= v5.1.1, which can be exploited by an attacker to obtain sensitivejpress · jpress · CWE-918 | Yüksek7,5 | — | %0,4 | 11 Eki 2024 |
29İzleyin | CVE-2021-46117İstismar yok | jpress 4.2.0 is vulnerable to remote code execution via io.jpress.module.page.PageNotifyKit#doSendEmail.jpress · jpress · CWE-94 | Yüksek7,2 | — | %2,8 | 26 Oca 2022 |
29İzleyin | CVE-2021-46118İstismar yok | jpress 4.2.0 is vulnerable to remote code execution via io.jpress.module.article.kit.ArticleNotifyKit#doSendEmail.jpress · jpress · CWE-94 | Yüksek7,2 | — | %2,3 | 26 Oca 2022 |
29İzleyin | CVE-2021-46116İstismar yok | jpress 4.2.0 is vulnerable to remote code execution via io.jpress.web.admin._TemplateController#doInstall.jpress · jpress · CWE-434 | Yüksek7,2 | — | %2,2 | 26 Oca 2022 |
28İzleyin | CVE-2021-46115İstismar yok | jpress 4.2.0 is vulnerable to RCE via io.jpress.web.admin._TemplateController#doUploadFile.jpress · jpress · CWE-434 | Yüksek7,2 | — | %1,1 | 26 Oca 2022 |
21İzleyin | CVE-2021-33347İstismar yok | An issue was discovered in JPress v3.3.0 and below.jpress · jpress · CWE-79 | Orta5,4 | — | %0,5 | 18 Haz 2021 |
21İzleyin | CVE-2024-11971İstismar yok | Guizhou Xiaoma Technology jpress Avatar upload cross site scriptingjpress · jpress · CWE-79 | Orta5,3 | — | %0,5 | 28 Kas 2024 |
21İzleyin | CVE-2019-6278İstismar yok | XSS exists in JPress v1.0.4 via Markdown input, or Markdown input with the code input option.jpress · jpress · CWE-79 | Orta5,4 | — | %0,5 | 14 Oca 2019 |
21İzleyin | CVE-2024-12348İstismar yok | Guizhou Xiaoma Technology jpress Attachment Upload upload AttachmentUtils.isUnSafe cross site scriptingjpress · jpress · CWE-79 | Orta5,3 | — | %0,4 | 8 Ara 2024 |
20İzleyin | CVE-2024-8304İstismar yok | jpress Template Module edit path traversaljpress · jpress · CWE-22 | Orta5,1 | — | %0,6 | 29 Ağu 2024 |
19İzleyin | CVE-2018-19170İstismar yok | In JPress v1.0-rc.5, there is stored XSS via each of the first three input fields to the starter-tomcat-1.0/admin/setting URI, as demonstratjpress · jpress · CWE-79 | Orta4,8 | — | %0,6 | 11 Kas 2018 |
- CVE-2021-4580740Planlayın
jpress v4.2.0 is vulnerable to command execution via io.jpress.web.admin._AddonController::doUploadAndInstall.
KritikCVSS 9,8İstismar yokEPSS %2jpress · jpress13 Oca 2022
- CVE-2024-5091939İzleyin
Jpress until v5.1.1 has arbitrary file uploads on the windows platform, and the construction of non-standard file formats such as .jsp.
KritikCVSS 9,8İstismar yokEPSS %1jpress · jpress18 Kas 2024
- CVE-2022-2333036İzleyin
A remote code execution (RCE) vulnerability in HelloWorldAddonController.java of jpress v4.2.0 allows attackers to execute arbitrary code vi
YüksekCVSS 8,8İstismar yokEPSS %2jpress · jpress4 Şub 2022
- CVE-2021-4580635İzleyin
jpress v4.2.0 admin panel provides a function through which attackers can modify the template and inject some malicious code.
YüksekCVSS 8,8İstismar yokEPSS %1jpress · jpress13 Oca 2022
- CVE-2021-4611435İzleyin
jpress v 4.2.0 is vulnerable to RCE via io.jpress.module.product.ProductNotifyKit#doSendEmail.
YüksekCVSS 8,8İstismar yokEPSS %1jpress · jpress26 Oca 2022
- CVE-2021-4580835İzleyin
jpress v4.2.0 allows users to register an account by default.
YüksekCVSS 8,8İstismar yokEPSS %1jpress · jpress19 Oca 2022
- CVE-2024-4303335İzleyin
JPress through 5.1.1 on Windows has an arbitrary file upload vulnerability that could cause arbitrary code execution via ::$DATA to Attachme
YüksekCVSS 8,8İstismar yokEPSS %1jpress · jpress21 Ağu 2024
- CVE-2024-3235830İzleyin
An issue in Jpress v.5.1.0 allows a remote attacker to execute arbitrary code via a crafted script to the custom plug-in module function, a
YüksekCVSS 7,5İstismar yokEPSS %1jpress · jpress25 Nis 2024
- CVE-2024-4646830İzleyin
A Server-Side Request Forgery (SSRF) vulnerability exists in the jpress <= v5.1.1, which can be exploited by an attacker to obtain sensitive
YüksekCVSS 7,5İstismar yokEPSS %0jpress · jpress11 Eki 2024
- CVE-2021-4611729İzleyin
jpress 4.2.0 is vulnerable to remote code execution via io.jpress.module.page.PageNotifyKit#doSendEmail.
YüksekCVSS 7,2İstismar yokEPSS %3jpress · jpress26 Oca 2022
- CVE-2021-4611829İzleyin
jpress 4.2.0 is vulnerable to remote code execution via io.jpress.module.article.kit.ArticleNotifyKit#doSendEmail.
YüksekCVSS 7,2İstismar yokEPSS %2jpress · jpress26 Oca 2022
- CVE-2021-4611629İzleyin
jpress 4.2.0 is vulnerable to remote code execution via io.jpress.web.admin._TemplateController#doInstall.
YüksekCVSS 7,2İstismar yokEPSS %2jpress · jpress26 Oca 2022
- CVE-2021-4611528İzleyin
jpress 4.2.0 is vulnerable to RCE via io.jpress.web.admin._TemplateController#doUploadFile.
YüksekCVSS 7,2İstismar yokEPSS %1jpress · jpress26 Oca 2022
- CVE-2021-3334721İzleyin
An issue was discovered in JPress v3.3.0 and below.
OrtaCVSS 5,4İstismar yokEPSS %1jpress · jpress18 Haz 2021
- CVE-2024-1197121İzleyin
Guizhou Xiaoma Technology jpress Avatar upload cross site scripting
OrtaCVSS 5,3İstismar yokEPSS %1jpress · jpress28 Kas 2024
- CVE-2019-627821İzleyin
XSS exists in JPress v1.0.4 via Markdown input, or Markdown input with the code input option.
OrtaCVSS 5,4İstismar yokEPSS %1jpress · jpress14 Oca 2019
- CVE-2024-1234821İzleyin
Guizhou Xiaoma Technology jpress Attachment Upload upload AttachmentUtils.isUnSafe cross site scripting
OrtaCVSS 5,3İstismar yokEPSS %0jpress · jpress8 Ara 2024
- CVE-2024-830420İzleyin
jpress Template Module edit path traversal
OrtaCVSS 5,1İstismar yokEPSS %1jpress · jpress29 Ağu 2024
- CVE-2018-1917019İzleyin
In JPress v1.0-rc.5, there is stored XSS via each of the first three input fields to the starter-tomcat-1.0/admin/setting URI, as demonstrat
OrtaCVSS 4,8İstismar yokEPSS %1jpress · jpress11 Kas 2018