Skip to content
Noroxi

jpress records

19 published records for vendor jpress.

All records

19 records
  • jpress v4.2.0 is vulnerable to command execution via io.jpress.web.admin._AddonController::doUploadAndInstall.

    CriticalCVSS 9.8No exploitEPSS 2%

    jpress · jpressJan 13, 2022

  • Jpress until v5.1.1 has arbitrary file uploads on the windows platform, and the construction of non-standard file formats such as .jsp.

    CriticalCVSS 9.8No exploitEPSS 1%

    jpress · jpressNov 18, 2024

  • A remote code execution (RCE) vulnerability in HelloWorldAddonController.java of jpress v4.2.0 allows attackers to execute arbitrary code vi

    HighCVSS 8.8No exploitEPSS 2%

    jpress · jpressFeb 4, 2022

  • jpress v4.2.0 admin panel provides a function through which attackers can modify the template and inject some malicious code.

    HighCVSS 8.8No exploitEPSS 1%

    jpress · jpressJan 13, 2022

  • jpress v 4.2.0 is vulnerable to RCE via io.jpress.module.product.ProductNotifyKit#doSendEmail.

    HighCVSS 8.8No exploitEPSS 1%

    jpress · jpressJan 26, 2022

  • jpress v4.2.0 allows users to register an account by default.

    HighCVSS 8.8No exploitEPSS 1%

    jpress · jpressJan 19, 2022

  • JPress through 5.1.1 on Windows has an arbitrary file upload vulnerability that could cause arbitrary code execution via ::$DATA to Attachme

    HighCVSS 8.8No exploitEPSS 1%

    jpress · jpressAug 21, 2024

  • An issue in Jpress v.5.1.0 allows a remote attacker to execute arbitrary code via a crafted script to the custom plug-in module function, a

    HighCVSS 7.5No exploitEPSS 1%

    jpress · jpressApr 25, 2024

  • A Server-Side Request Forgery (SSRF) vulnerability exists in the jpress <= v5.1.1, which can be exploited by an attacker to obtain sensitive

    HighCVSS 7.5No exploitEPSS 0%

    jpress · jpressOct 11, 2024

  • jpress 4.2.0 is vulnerable to remote code execution via io.jpress.module.page.PageNotifyKit#doSendEmail.

    HighCVSS 7.2No exploitEPSS 3%

    jpress · jpressJan 26, 2022

  • jpress 4.2.0 is vulnerable to remote code execution via io.jpress.module.article.kit.ArticleNotifyKit#doSendEmail.

    HighCVSS 7.2No exploitEPSS 2%

    jpress · jpressJan 26, 2022

  • jpress 4.2.0 is vulnerable to remote code execution via io.jpress.web.admin._TemplateController#doInstall.

    HighCVSS 7.2No exploitEPSS 2%

    jpress · jpressJan 26, 2022

  • jpress 4.2.0 is vulnerable to RCE via io.jpress.web.admin._TemplateController#doUploadFile.

    HighCVSS 7.2No exploitEPSS 1%

    jpress · jpressJan 26, 2022

  • An issue was discovered in JPress v3.3.0 and below.

    MediumCVSS 5.4No exploitEPSS 1%

    jpress · jpressJun 18, 2021

  • Guizhou Xiaoma Technology jpress Avatar upload cross site scripting

    MediumCVSS 5.3No exploitEPSS 1%

    jpress · jpressNov 28, 2024

  • CVE-2019-6278
    21Monitor

    XSS exists in JPress v1.0.4 via Markdown input, or Markdown input with the code input option.

    MediumCVSS 5.4No exploitEPSS 1%

    jpress · jpressJan 14, 2019

  • Guizhou Xiaoma Technology jpress Attachment Upload upload AttachmentUtils.isUnSafe cross site scripting

    MediumCVSS 5.3No exploitEPSS 0%

    jpress · jpressDec 8, 2024

  • CVE-2024-8304
    20Monitor

    jpress Template Module edit path traversal

    MediumCVSS 5.1No exploitEPSS 1%

    jpress · jpressAug 29, 2024

  • In JPress v1.0-rc.5, there is stored XSS via each of the first three input fields to the starter-tomcat-1.0/admin/setting URI, as demonstrat

    MediumCVSS 4.8No exploitEPSS 1%

    jpress · jpressNov 11, 2018