Перейти к содержимому
Noroxi

Записи jeesns

21 опубликованных записей вендора jeesns.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
4
С записью об исправлении
0 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Записи по годам

  1. 18
  2. 21
  3. 22

Столбик: всего · тёмная часть: CISA KEV.

Повторяющиеся классы

Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.

CWE

Все записи

21 записей
  • CVE-2020-19280
    35Наблюдать

    Jeesns 1.4.2 contains a cross-site request forgery (CSRF) which allows attackers to escalate privileges and perform sensitive program operat

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    jeesns · jeesns9 сент. 2021 г.

  • CVE-2020-19295
    25Наблюдать

    A reflected cross-site scripting (XSS) vulnerability in the /weibo/topic component of Jeesns 1.4.2 allows attackers to execute arbitrary web

    СредняяCVSS 6,1Proof of conceptEPSS 4 %

    jeesns · jeesns9 сент. 2021 г.

  • CVE-2020-19282
    25Наблюдать

    A reflected cross-site scripting (XSS) vulnerability in Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted

    СредняяCVSS 6,1Proof of conceptEPSS 3 %

    jeesns · jeesns9 сент. 2021 г.

  • CVE-2020-19283
    25Наблюдать

    A reflected cross-site scripting (XSS) vulnerability in the /newVersion component of Jeesns 1.4.2 allows attackers to execute arbitrary web

    СредняяCVSS 6,1Proof of conceptEPSS 3 %

    jeesns · jeesns9 сент. 2021 г.

  • CVE-2020-18035
    24Наблюдать

    Cross Site Scripting (XSS) in Jeesns v1.4.2 allows remote attackers to execute arbitrary code by injecting commands into the "CKEditorFuncNu

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    jeesns · jeesns29 апр. 2021 г.

  • CVE-2020-19287
    21Наблюдать

    A stored cross-site scripting (XSS) vulnerability in the /group/post component of Jeesns 1.4.2 allows attackers to execute arbitrary web scr

    СредняяCVSS 5,4Эксплойта нетEPSS 1 %

    jeesns · jeesns9 сент. 2021 г.

  • CVE-2020-19291
    21Наблюдать

    A stored cross-site scripting (XSS) vulnerability in the /weibo/publishdata component of Jeesns 1.4.2 allows attackers to execute arbitrary

    СредняяCVSS 5,4Эксплойта нетEPSS 1 %

    jeesns · jeesns9 сент. 2021 г.

  • CVE-2018-17886
    21Наблюдать

    An issue was discovered in JEESNS 1.3.

    СредняяCVSS 5,4Эксплойта нетEPSS 1 %

    jeesns · jeesns2 окт. 2018 г.

  • CVE-2020-19285
    21Наблюдать

    A stored cross-site scripting (XSS) vulnerability in the /group/apply component of Jeesns 1.4.2 allows attackers to execute arbitrary web sc

    СредняяCVSS 5,4Эксплойта нетEPSS 1 %

    jeesns · jeesns9 сент. 2021 г.

  • CVE-2020-19289
    21Наблюдать

    A stored cross-site scripting (XSS) vulnerability in the /member/picture/album component of Jeesns 1.4.2 allows attackers to execute arbitra

    СредняяCVSS 5,4Эксплойта нетEPSS 1 %

    jeesns · jeesns9 сент. 2021 г.

  • CVE-2020-19292
    21Наблюдать

    A stored cross-site scripting (XSS) vulnerability in the /question/ask component of Jeesns 1.4.2 allows attackers to execute arbitrary web s

    СредняяCVSS 5,4Эксплойта нетEPSS 1 %

    jeesns · jeesns9 сент. 2021 г.

  • CVE-2020-19293
    21Наблюдать

    A stored cross-site scripting (XSS) vulnerability in the /article/add component of Jeesns 1.4.2 allows attackers to execute arbitrary web sc

    СредняяCVSS 5,4Эксплойта нетEPSS 1 %

    jeesns · jeesns9 сент. 2021 г.

  • CVE-2020-19286
    21Наблюдать

    A stored cross-site scripting (XSS) vulnerability in the /question/detail component of Jeesns 1.4.2 allows attackers to execute arbitrary we

    СредняяCVSS 5,4Эксплойта нетEPSS 1 %

    jeesns · jeesns9 сент. 2021 г.

  • CVE-2020-19281
    21Наблюдать

    A stored cross-site scripting (XSS) vulnerability in the /manage/loginusername component of Jeesns 1.4.2 allows attackers to execute arbitra

    СредняяCVSS 5,4Эксплойта нетEPSS 1 %

    jeesns · jeesns9 сент. 2021 г.

  • CVE-2018-19178
    21Наблюдать

    In JEESNS 1.3, com/lxinet/jeesns/core/utils/XssHttpServletRequestWrapper.java allows stored XSS via an HTML EMBED element, a different vulne

    СредняяCVSS 5,4Эксплойта нетEPSS 1 %

    jeesns · jeesns11 нояб. 2018 г.

  • CVE-2020-19284
    21Наблюдать

    A stored cross-site scripting (XSS) vulnerability in the /group/comment component of Jeesns 1.4.2 allows attackers to execute arbitrary web

    СредняяCVSS 5,4Эксплойта нетEPSS 1 %

    jeesns · jeesns9 сент. 2021 г.

  • CVE-2020-19288
    21Наблюдать

    A stored cross-site scripting (XSS) vulnerability in the /localhost/u component of Jeesns 1.4.2 allows attackers to execute arbitrary web sc

    СредняяCVSS 5,4Эксплойта нетEPSS 1 %

    jeesns · jeesns9 сент. 2021 г.

  • CVE-2020-19294
    21Наблюдать

    A stored cross-site scripting (XSS) vulnerability in the /article/comment component of Jeesns 1.4.2 allows attackers to execute arbitrary we

    СредняяCVSS 5,4Эксплойта нетEPSS 1 %

    jeesns · jeesns9 сент. 2021 г.

  • CVE-2020-19290
    21Наблюдать

    A stored cross-site scripting (XSS) vulnerability in the /weibo/comment component of Jeesns 1.4.2 allows attackers to execute arbitrary web

    СредняяCVSS 5,4Эксплойта нетEPSS 1 %

    jeesns · jeesns9 сент. 2021 г.

  • CVE-2018-12429
    21Наблюдать

    JEESNS through 1.2.1 allows XSS attacks by ordinary users who publish articles containing a crafted payload in order to capture an administr

    СредняяCVSS 5,4Эксплойта нетEPSS 1 %

    jeesns · jeesns18 июл. 2018 г.

  • CVE-2022-38550
    21Наблюдать

    A stored cross-site scripting (XSS) vulnerability in the /weibo/list component of Jeesns v2.0.0 allows attackers to execute arbitrary web sc

    СредняяCVSS 5,4Эксплойта нетEPSS 0 %

    jeesns · jeesns19 сент. 2022 г.