jpress records
19 published records for vendor jpress.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 3
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-94 Improper Control of Generation of Code ('Code Injection')6
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')5
- CWE-434 Unrestricted Upload of File with Dangerous Type3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-69 Improper Handling of Windows ::DATA Alternate Data Stream1
- CWE-918 Server-Side Request Forgery (SSRF)1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
19 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2021-45807No exploit | jpress v4.2.0 is vulnerable to command execution via io.jpress.web.admin._AddonController::doUploadAndInstall.jpress · jpress | Critical9.8 | — | 2.1% | Jan 13, 2022 |
39Monitor | CVE-2024-50919No exploit | Jpress until v5.1.1 has arbitrary file uploads on the windows platform, and the construction of non-standard file formats such as .jsp.jpress · jpress · CWE-94 | Critical9.8 | — | 1.2% | Nov 18, 2024 |
36Monitor | CVE-2022-23330No exploit | A remote code execution (RCE) vulnerability in HelloWorldAddonController.java of jpress v4.2.0 allows attackers to execute arbitrary code vijpress · jpress | High8.8 | — | 1.9% | Feb 4, 2022 |
35Monitor | CVE-2021-45806No exploit | jpress v4.2.0 admin panel provides a function through which attackers can modify the template and inject some malicious code.jpress · jpress · CWE-94 | High8.8 | — | 1.4% | Jan 13, 2022 |
35Monitor | CVE-2021-46114No exploit | jpress v 4.2.0 is vulnerable to RCE via io.jpress.module.product.ProductNotifyKit#doSendEmail.jpress · jpress · CWE-94 | High8.8 | — | 1.3% | Jan 26, 2022 |
35Monitor | CVE-2021-45808No exploit | jpress v4.2.0 allows users to register an account by default.jpress · jpress · CWE-434 | High8.8 | — | 1.3% | Jan 19, 2022 |
35Monitor | CVE-2024-43033No exploit | JPress through 5.1.1 on Windows has an arbitrary file upload vulnerability that could cause arbitrary code execution via ::$DATA to Attachmejpress · jpress · CWE-69 | High8.8 | — | 1.0% | Aug 21, 2024 |
30Monitor | CVE-2024-32358No exploit | An issue in Jpress v.5.1.0 allows a remote attacker to execute arbitrary code via a crafted script to the custom plug-in module function, a jpress · jpress · CWE-94 | High7.5 | — | 0.7% | Apr 25, 2024 |
30Monitor | CVE-2024-46468No exploit | A Server-Side Request Forgery (SSRF) vulnerability exists in the jpress <= v5.1.1, which can be exploited by an attacker to obtain sensitivejpress · jpress · CWE-918 | High7.5 | — | 0.4% | Oct 11, 2024 |
29Monitor | CVE-2021-46117No exploit | jpress 4.2.0 is vulnerable to remote code execution via io.jpress.module.page.PageNotifyKit#doSendEmail.jpress · jpress · CWE-94 | High7.2 | — | 2.8% | Jan 26, 2022 |
29Monitor | CVE-2021-46118No exploit | jpress 4.2.0 is vulnerable to remote code execution via io.jpress.module.article.kit.ArticleNotifyKit#doSendEmail.jpress · jpress · CWE-94 | High7.2 | — | 2.3% | Jan 26, 2022 |
29Monitor | CVE-2021-46116No exploit | jpress 4.2.0 is vulnerable to remote code execution via io.jpress.web.admin._TemplateController#doInstall.jpress · jpress · CWE-434 | High7.2 | — | 2.2% | Jan 26, 2022 |
28Monitor | CVE-2021-46115No exploit | jpress 4.2.0 is vulnerable to RCE via io.jpress.web.admin._TemplateController#doUploadFile.jpress · jpress · CWE-434 | High7.2 | — | 1.1% | Jan 26, 2022 |
21Monitor | CVE-2021-33347No exploit | An issue was discovered in JPress v3.3.0 and below.jpress · jpress · CWE-79 | Medium5.4 | — | 0.5% | Jun 18, 2021 |
21Monitor | CVE-2024-11971No exploit | Guizhou Xiaoma Technology jpress Avatar upload cross site scriptingjpress · jpress · CWE-79 | Medium5.3 | — | 0.5% | Nov 28, 2024 |
21Monitor | CVE-2019-6278No exploit | XSS exists in JPress v1.0.4 via Markdown input, or Markdown input with the code input option.jpress · jpress · CWE-79 | Medium5.4 | — | 0.5% | Jan 14, 2019 |
21Monitor | CVE-2024-12348No exploit | Guizhou Xiaoma Technology jpress Attachment Upload upload AttachmentUtils.isUnSafe cross site scriptingjpress · jpress · CWE-79 | Medium5.3 | — | 0.4% | Dec 8, 2024 |
20Monitor | CVE-2024-8304No exploit | jpress Template Module edit path traversaljpress · jpress · CWE-22 | Medium5.1 | — | 0.6% | Aug 29, 2024 |
19Monitor | CVE-2018-19170No exploit | In JPress v1.0-rc.5, there is stored XSS via each of the first three input fields to the starter-tomcat-1.0/admin/setting URI, as demonstratjpress · jpress · CWE-79 | Medium4.8 | — | 0.6% | Nov 11, 2018 |
- CVE-2021-4580740Plan
jpress v4.2.0 is vulnerable to command execution via io.jpress.web.admin._AddonController::doUploadAndInstall.
CriticalCVSS 9.8No exploitEPSS 2%jpress · jpressJan 13, 2022
- CVE-2024-5091939Monitor
Jpress until v5.1.1 has arbitrary file uploads on the windows platform, and the construction of non-standard file formats such as .jsp.
CriticalCVSS 9.8No exploitEPSS 1%jpress · jpressNov 18, 2024
- CVE-2022-2333036Monitor
A remote code execution (RCE) vulnerability in HelloWorldAddonController.java of jpress v4.2.0 allows attackers to execute arbitrary code vi
HighCVSS 8.8No exploitEPSS 2%jpress · jpressFeb 4, 2022
- CVE-2021-4580635Monitor
jpress v4.2.0 admin panel provides a function through which attackers can modify the template and inject some malicious code.
HighCVSS 8.8No exploitEPSS 1%jpress · jpressJan 13, 2022
- CVE-2021-4611435Monitor
jpress v 4.2.0 is vulnerable to RCE via io.jpress.module.product.ProductNotifyKit#doSendEmail.
HighCVSS 8.8No exploitEPSS 1%jpress · jpressJan 26, 2022
- CVE-2021-4580835Monitor
jpress v4.2.0 allows users to register an account by default.
HighCVSS 8.8No exploitEPSS 1%jpress · jpressJan 19, 2022
- CVE-2024-4303335Monitor
JPress through 5.1.1 on Windows has an arbitrary file upload vulnerability that could cause arbitrary code execution via ::$DATA to Attachme
HighCVSS 8.8No exploitEPSS 1%jpress · jpressAug 21, 2024
- CVE-2024-3235830Monitor
An issue in Jpress v.5.1.0 allows a remote attacker to execute arbitrary code via a crafted script to the custom plug-in module function, a
HighCVSS 7.5No exploitEPSS 1%jpress · jpressApr 25, 2024
- CVE-2024-4646830Monitor
A Server-Side Request Forgery (SSRF) vulnerability exists in the jpress <= v5.1.1, which can be exploited by an attacker to obtain sensitive
HighCVSS 7.5No exploitEPSS 0%jpress · jpressOct 11, 2024
- CVE-2021-4611729Monitor
jpress 4.2.0 is vulnerable to remote code execution via io.jpress.module.page.PageNotifyKit#doSendEmail.
HighCVSS 7.2No exploitEPSS 3%jpress · jpressJan 26, 2022
- CVE-2021-4611829Monitor
jpress 4.2.0 is vulnerable to remote code execution via io.jpress.module.article.kit.ArticleNotifyKit#doSendEmail.
HighCVSS 7.2No exploitEPSS 2%jpress · jpressJan 26, 2022
- CVE-2021-4611629Monitor
jpress 4.2.0 is vulnerable to remote code execution via io.jpress.web.admin._TemplateController#doInstall.
HighCVSS 7.2No exploitEPSS 2%jpress · jpressJan 26, 2022
- CVE-2021-4611528Monitor
jpress 4.2.0 is vulnerable to RCE via io.jpress.web.admin._TemplateController#doUploadFile.
HighCVSS 7.2No exploitEPSS 1%jpress · jpressJan 26, 2022
- CVE-2021-3334721Monitor
An issue was discovered in JPress v3.3.0 and below.
MediumCVSS 5.4No exploitEPSS 1%jpress · jpressJun 18, 2021
- CVE-2024-1197121Monitor
Guizhou Xiaoma Technology jpress Avatar upload cross site scripting
MediumCVSS 5.3No exploitEPSS 1%jpress · jpressNov 28, 2024
- CVE-2019-627821Monitor
XSS exists in JPress v1.0.4 via Markdown input, or Markdown input with the code input option.
MediumCVSS 5.4No exploitEPSS 1%jpress · jpressJan 14, 2019
- CVE-2024-1234821Monitor
Guizhou Xiaoma Technology jpress Attachment Upload upload AttachmentUtils.isUnSafe cross site scripting
MediumCVSS 5.3No exploitEPSS 0%jpress · jpressDec 8, 2024
- CVE-2024-830420Monitor
jpress Template Module edit path traversal
MediumCVSS 5.1No exploitEPSS 1%jpress · jpressAug 29, 2024
- CVE-2018-1917019Monitor
In JPress v1.0-rc.5, there is stored XSS via each of the first three input fields to the starter-tomcat-1.0/admin/setting URI, as demonstrat
MediumCVSS 4.8No exploitEPSS 1%jpress · jpressNov 11, 2018