Записи jeesns
21 опубликованных записей вендора jeesns.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 4
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')20
- CWE-352 Cross-Site Request Forgery (CSRF)1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEПрофиль атаки
Все записи
21 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
35Наблюдать | CVE-2020-19280Эксплойта нет | Jeesns 1.4.2 contains a cross-site request forgery (CSRF) which allows attackers to escalate privileges and perform sensitive program operatjeesns · jeesns · CWE-352 | Высокая8,8 | — | 0,9 % | 9 сент. 2021 г. |
25Наблюдать | CVE-2020-19295Proof of concept | A reflected cross-site scripting (XSS) vulnerability in the /weibo/topic component of Jeesns 1.4.2 allows attackers to execute arbitrary webjeesns · jeesns · CWE-79 | Средняя6,1 | — | 3,5 % | 9 сент. 2021 г. |
25Наблюдать | CVE-2020-19282Proof of concept | A reflected cross-site scripting (XSS) vulnerability in Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a craftedjeesns · jeesns · CWE-79 | Средняя6,1 | — | 3,2 % | 9 сент. 2021 г. |
25Наблюдать | CVE-2020-19283Proof of concept | A reflected cross-site scripting (XSS) vulnerability in the /newVersion component of Jeesns 1.4.2 allows attackers to execute arbitrary web jeesns · jeesns · CWE-79 | Средняя6,1 | — | 2,6 % | 9 сент. 2021 г. |
24Наблюдать | CVE-2020-18035Эксплойта нет | Cross Site Scripting (XSS) in Jeesns v1.4.2 allows remote attackers to execute arbitrary code by injecting commands into the "CKEditorFuncNujeesns · jeesns · CWE-79 | Средняя6,1 | — | 1,0 % | 29 апр. 2021 г. |
21Наблюдать | CVE-2020-19287Эксплойта нет | A stored cross-site scripting (XSS) vulnerability in the /group/post component of Jeesns 1.4.2 allows attackers to execute arbitrary web scrjeesns · jeesns · CWE-79 | Средняя5,4 | — | 0,7 % | 9 сент. 2021 г. |
21Наблюдать | CVE-2020-19291Эксплойта нет | A stored cross-site scripting (XSS) vulnerability in the /weibo/publishdata component of Jeesns 1.4.2 allows attackers to execute arbitrary jeesns · jeesns · CWE-79 | Средняя5,4 | — | 0,7 % | 9 сент. 2021 г. |
21Наблюдать | CVE-2018-17886Эксплойта нет | An issue was discovered in JEESNS 1.3.jeesns · jeesns · CWE-79 | Средняя5,4 | — | 0,7 % | 2 окт. 2018 г. |
21Наблюдать | CVE-2020-19285Эксплойта нет | A stored cross-site scripting (XSS) vulnerability in the /group/apply component of Jeesns 1.4.2 allows attackers to execute arbitrary web scjeesns · jeesns · CWE-79 | Средняя5,4 | — | 0,7 % | 9 сент. 2021 г. |
21Наблюдать | CVE-2020-19289Эксплойта нет | A stored cross-site scripting (XSS) vulnerability in the /member/picture/album component of Jeesns 1.4.2 allows attackers to execute arbitrajeesns · jeesns · CWE-79 | Средняя5,4 | — | 0,7 % | 9 сент. 2021 г. |
21Наблюдать | CVE-2020-19292Эксплойта нет | A stored cross-site scripting (XSS) vulnerability in the /question/ask component of Jeesns 1.4.2 allows attackers to execute arbitrary web sjeesns · jeesns · CWE-79 | Средняя5,4 | — | 0,6 % | 9 сент. 2021 г. |
21Наблюдать | CVE-2020-19293Эксплойта нет | A stored cross-site scripting (XSS) vulnerability in the /article/add component of Jeesns 1.4.2 allows attackers to execute arbitrary web scjeesns · jeesns · CWE-79 | Средняя5,4 | — | 0,6 % | 9 сент. 2021 г. |
21Наблюдать | CVE-2020-19286Эксплойта нет | A stored cross-site scripting (XSS) vulnerability in the /question/detail component of Jeesns 1.4.2 allows attackers to execute arbitrary wejeesns · jeesns · CWE-79 | Средняя5,4 | — | 0,6 % | 9 сент. 2021 г. |
21Наблюдать | CVE-2020-19281Эксплойта нет | A stored cross-site scripting (XSS) vulnerability in the /manage/loginusername component of Jeesns 1.4.2 allows attackers to execute arbitrajeesns · jeesns · CWE-79 | Средняя5,4 | — | 0,6 % | 9 сент. 2021 г. |
21Наблюдать | CVE-2018-19178Эксплойта нет | In JEESNS 1.3, com/lxinet/jeesns/core/utils/XssHttpServletRequestWrapper.java allows stored XSS via an HTML EMBED element, a different vulnejeesns · jeesns · CWE-79 | Средняя5,4 | — | 0,6 % | 11 нояб. 2018 г. |
21Наблюдать | CVE-2020-19284Эксплойта нет | A stored cross-site scripting (XSS) vulnerability in the /group/comment component of Jeesns 1.4.2 allows attackers to execute arbitrary web jeesns · jeesns · CWE-79 | Средняя5,4 | — | 0,5 % | 9 сент. 2021 г. |
21Наблюдать | CVE-2020-19288Эксплойта нет | A stored cross-site scripting (XSS) vulnerability in the /localhost/u component of Jeesns 1.4.2 allows attackers to execute arbitrary web scjeesns · jeesns · CWE-79 | Средняя5,4 | — | 0,5 % | 9 сент. 2021 г. |
21Наблюдать | CVE-2020-19294Эксплойта нет | A stored cross-site scripting (XSS) vulnerability in the /article/comment component of Jeesns 1.4.2 allows attackers to execute arbitrary wejeesns · jeesns · CWE-79 | Средняя5,4 | — | 0,5 % | 9 сент. 2021 г. |
21Наблюдать | CVE-2020-19290Эксплойта нет | A stored cross-site scripting (XSS) vulnerability in the /weibo/comment component of Jeesns 1.4.2 allows attackers to execute arbitrary web jeesns · jeesns · CWE-79 | Средняя5,4 | — | 0,5 % | 9 сент. 2021 г. |
21Наблюдать | CVE-2018-12429Эксплойта нет | JEESNS through 1.2.1 allows XSS attacks by ordinary users who publish articles containing a crafted payload in order to capture an administrjeesns · jeesns · CWE-79 | Средняя5,4 | — | 0,5 % | 18 июл. 2018 г. |
21Наблюдать | CVE-2022-38550Эксплойта нет | A stored cross-site scripting (XSS) vulnerability in the /weibo/list component of Jeesns v2.0.0 allows attackers to execute arbitrary web scjeesns · jeesns · CWE-79 | Средняя5,4 | — | 0,5 % | 19 сент. 2022 г. |
- CVE-2020-1928035Наблюдать
Jeesns 1.4.2 contains a cross-site request forgery (CSRF) which allows attackers to escalate privileges and perform sensitive program operat
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %jeesns · jeesns9 сент. 2021 г.
- CVE-2020-1929525Наблюдать
A reflected cross-site scripting (XSS) vulnerability in the /weibo/topic component of Jeesns 1.4.2 allows attackers to execute arbitrary web
СредняяCVSS 6,1Proof of conceptEPSS 4 %jeesns · jeesns9 сент. 2021 г.
- CVE-2020-1928225Наблюдать
A reflected cross-site scripting (XSS) vulnerability in Jeesns 1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted
СредняяCVSS 6,1Proof of conceptEPSS 3 %jeesns · jeesns9 сент. 2021 г.
- CVE-2020-1928325Наблюдать
A reflected cross-site scripting (XSS) vulnerability in the /newVersion component of Jeesns 1.4.2 allows attackers to execute arbitrary web
СредняяCVSS 6,1Proof of conceptEPSS 3 %jeesns · jeesns9 сент. 2021 г.
- CVE-2020-1803524Наблюдать
Cross Site Scripting (XSS) in Jeesns v1.4.2 allows remote attackers to execute arbitrary code by injecting commands into the "CKEditorFuncNu
СредняяCVSS 6,1Эксплойта нетEPSS 1 %jeesns · jeesns29 апр. 2021 г.
- CVE-2020-1928721Наблюдать
A stored cross-site scripting (XSS) vulnerability in the /group/post component of Jeesns 1.4.2 allows attackers to execute arbitrary web scr
СредняяCVSS 5,4Эксплойта нетEPSS 1 %jeesns · jeesns9 сент. 2021 г.
- CVE-2020-1929121Наблюдать
A stored cross-site scripting (XSS) vulnerability in the /weibo/publishdata component of Jeesns 1.4.2 allows attackers to execute arbitrary
СредняяCVSS 5,4Эксплойта нетEPSS 1 %jeesns · jeesns9 сент. 2021 г.
- CVE-2018-1788621Наблюдать
An issue was discovered in JEESNS 1.3.
СредняяCVSS 5,4Эксплойта нетEPSS 1 %jeesns · jeesns2 окт. 2018 г.
- CVE-2020-1928521Наблюдать
A stored cross-site scripting (XSS) vulnerability in the /group/apply component of Jeesns 1.4.2 allows attackers to execute arbitrary web sc
СредняяCVSS 5,4Эксплойта нетEPSS 1 %jeesns · jeesns9 сент. 2021 г.
- CVE-2020-1928921Наблюдать
A stored cross-site scripting (XSS) vulnerability in the /member/picture/album component of Jeesns 1.4.2 allows attackers to execute arbitra
СредняяCVSS 5,4Эксплойта нетEPSS 1 %jeesns · jeesns9 сент. 2021 г.
- CVE-2020-1929221Наблюдать
A stored cross-site scripting (XSS) vulnerability in the /question/ask component of Jeesns 1.4.2 allows attackers to execute arbitrary web s
СредняяCVSS 5,4Эксплойта нетEPSS 1 %jeesns · jeesns9 сент. 2021 г.
- CVE-2020-1929321Наблюдать
A stored cross-site scripting (XSS) vulnerability in the /article/add component of Jeesns 1.4.2 allows attackers to execute arbitrary web sc
СредняяCVSS 5,4Эксплойта нетEPSS 1 %jeesns · jeesns9 сент. 2021 г.
- CVE-2020-1928621Наблюдать
A stored cross-site scripting (XSS) vulnerability in the /question/detail component of Jeesns 1.4.2 allows attackers to execute arbitrary we
СредняяCVSS 5,4Эксплойта нетEPSS 1 %jeesns · jeesns9 сент. 2021 г.
- CVE-2020-1928121Наблюдать
A stored cross-site scripting (XSS) vulnerability in the /manage/loginusername component of Jeesns 1.4.2 allows attackers to execute arbitra
СредняяCVSS 5,4Эксплойта нетEPSS 1 %jeesns · jeesns9 сент. 2021 г.
- CVE-2018-1917821Наблюдать
In JEESNS 1.3, com/lxinet/jeesns/core/utils/XssHttpServletRequestWrapper.java allows stored XSS via an HTML EMBED element, a different vulne
СредняяCVSS 5,4Эксплойта нетEPSS 1 %jeesns · jeesns11 нояб. 2018 г.
- CVE-2020-1928421Наблюдать
A stored cross-site scripting (XSS) vulnerability in the /group/comment component of Jeesns 1.4.2 allows attackers to execute arbitrary web
СредняяCVSS 5,4Эксплойта нетEPSS 1 %jeesns · jeesns9 сент. 2021 г.
- CVE-2020-1928821Наблюдать
A stored cross-site scripting (XSS) vulnerability in the /localhost/u component of Jeesns 1.4.2 allows attackers to execute arbitrary web sc
СредняяCVSS 5,4Эксплойта нетEPSS 1 %jeesns · jeesns9 сент. 2021 г.
- CVE-2020-1929421Наблюдать
A stored cross-site scripting (XSS) vulnerability in the /article/comment component of Jeesns 1.4.2 allows attackers to execute arbitrary we
СредняяCVSS 5,4Эксплойта нетEPSS 1 %jeesns · jeesns9 сент. 2021 г.
- CVE-2020-1929021Наблюдать
A stored cross-site scripting (XSS) vulnerability in the /weibo/comment component of Jeesns 1.4.2 allows attackers to execute arbitrary web
СредняяCVSS 5,4Эксплойта нетEPSS 1 %jeesns · jeesns9 сент. 2021 г.
- CVE-2018-1242921Наблюдать
JEESNS through 1.2.1 allows XSS attacks by ordinary users who publish articles containing a crafted payload in order to capture an administr
СредняяCVSS 5,4Эксплойта нетEPSS 1 %jeesns · jeesns18 июл. 2018 г.
- CVE-2022-3855021Наблюдать
A stored cross-site scripting (XSS) vulnerability in the /weibo/list component of Jeesns v2.0.0 allows attackers to execute arbitrary web sc
СредняяCVSS 5,4Эксплойта нетEPSS 0 %jeesns · jeesns19 сент. 2022 г.