Записи jpress
19 опубликованных записей вендора jpress.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 3
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-94 Improper Control of Generation of Code ('Code Injection')6
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')5
- CWE-434 Unrestricted Upload of File with Dangerous Type3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-69 Improper Handling of Windows ::DATA Alternate Data Stream1
- CWE-918 Server-Side Request Forgery (SSRF)1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
19 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2021-45807Эксплойта нет | jpress v4.2.0 is vulnerable to command execution via io.jpress.web.admin._AddonController::doUploadAndInstall.jpress · jpress | Критическая9,8 | — | 2,1 % | 13 янв. 2022 г. |
39Наблюдать | CVE-2024-50919Эксплойта нет | Jpress until v5.1.1 has arbitrary file uploads on the windows platform, and the construction of non-standard file formats such as .jsp.jpress · jpress · CWE-94 | Критическая9,8 | — | 1,2 % | 18 нояб. 2024 г. |
36Наблюдать | CVE-2022-23330Эксплойта нет | A remote code execution (RCE) vulnerability in HelloWorldAddonController.java of jpress v4.2.0 allows attackers to execute arbitrary code vijpress · jpress | Высокая8,8 | — | 1,9 % | 4 февр. 2022 г. |
35Наблюдать | CVE-2021-45806Эксплойта нет | jpress v4.2.0 admin panel provides a function through which attackers can modify the template and inject some malicious code.jpress · jpress · CWE-94 | Высокая8,8 | — | 1,4 % | 13 янв. 2022 г. |
35Наблюдать | CVE-2021-46114Эксплойта нет | jpress v 4.2.0 is vulnerable to RCE via io.jpress.module.product.ProductNotifyKit#doSendEmail.jpress · jpress · CWE-94 | Высокая8,8 | — | 1,3 % | 26 янв. 2022 г. |
35Наблюдать | CVE-2021-45808Эксплойта нет | jpress v4.2.0 allows users to register an account by default.jpress · jpress · CWE-434 | Высокая8,8 | — | 1,3 % | 19 янв. 2022 г. |
35Наблюдать | CVE-2024-43033Эксплойта нет | JPress through 5.1.1 on Windows has an arbitrary file upload vulnerability that could cause arbitrary code execution via ::$DATA to Attachmejpress · jpress · CWE-69 | Высокая8,8 | — | 1,0 % | 21 авг. 2024 г. |
30Наблюдать | CVE-2024-32358Эксплойта нет | An issue in Jpress v.5.1.0 allows a remote attacker to execute arbitrary code via a crafted script to the custom plug-in module function, a jpress · jpress · CWE-94 | Высокая7,5 | — | 0,7 % | 25 апр. 2024 г. |
30Наблюдать | CVE-2024-46468Эксплойта нет | A Server-Side Request Forgery (SSRF) vulnerability exists in the jpress <= v5.1.1, which can be exploited by an attacker to obtain sensitivejpress · jpress · CWE-918 | Высокая7,5 | — | 0,4 % | 11 окт. 2024 г. |
29Наблюдать | CVE-2021-46117Эксплойта нет | jpress 4.2.0 is vulnerable to remote code execution via io.jpress.module.page.PageNotifyKit#doSendEmail.jpress · jpress · CWE-94 | Высокая7,2 | — | 2,8 % | 26 янв. 2022 г. |
29Наблюдать | CVE-2021-46118Эксплойта нет | jpress 4.2.0 is vulnerable to remote code execution via io.jpress.module.article.kit.ArticleNotifyKit#doSendEmail.jpress · jpress · CWE-94 | Высокая7,2 | — | 2,3 % | 26 янв. 2022 г. |
29Наблюдать | CVE-2021-46116Эксплойта нет | jpress 4.2.0 is vulnerable to remote code execution via io.jpress.web.admin._TemplateController#doInstall.jpress · jpress · CWE-434 | Высокая7,2 | — | 2,2 % | 26 янв. 2022 г. |
28Наблюдать | CVE-2021-46115Эксплойта нет | jpress 4.2.0 is vulnerable to RCE via io.jpress.web.admin._TemplateController#doUploadFile.jpress · jpress · CWE-434 | Высокая7,2 | — | 1,1 % | 26 янв. 2022 г. |
21Наблюдать | CVE-2021-33347Эксплойта нет | An issue was discovered in JPress v3.3.0 and below.jpress · jpress · CWE-79 | Средняя5,4 | — | 0,5 % | 18 июн. 2021 г. |
21Наблюдать | CVE-2024-11971Эксплойта нет | Guizhou Xiaoma Technology jpress Avatar upload cross site scriptingjpress · jpress · CWE-79 | Средняя5,3 | — | 0,5 % | 28 нояб. 2024 г. |
21Наблюдать | CVE-2019-6278Эксплойта нет | XSS exists in JPress v1.0.4 via Markdown input, or Markdown input with the code input option.jpress · jpress · CWE-79 | Средняя5,4 | — | 0,5 % | 14 янв. 2019 г. |
21Наблюдать | CVE-2024-12348Эксплойта нет | Guizhou Xiaoma Technology jpress Attachment Upload upload AttachmentUtils.isUnSafe cross site scriptingjpress · jpress · CWE-79 | Средняя5,3 | — | 0,4 % | 8 дек. 2024 г. |
20Наблюдать | CVE-2024-8304Эксплойта нет | jpress Template Module edit path traversaljpress · jpress · CWE-22 | Средняя5,1 | — | 0,6 % | 29 авг. 2024 г. |
19Наблюдать | CVE-2018-19170Эксплойта нет | In JPress v1.0-rc.5, there is stored XSS via each of the first three input fields to the starter-tomcat-1.0/admin/setting URI, as demonstratjpress · jpress · CWE-79 | Средняя4,8 | — | 0,6 % | 11 нояб. 2018 г. |
- CVE-2021-4580740В плане
jpress v4.2.0 is vulnerable to command execution via io.jpress.web.admin._AddonController::doUploadAndInstall.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %jpress · jpress13 янв. 2022 г.
- CVE-2024-5091939Наблюдать
Jpress until v5.1.1 has arbitrary file uploads on the windows platform, and the construction of non-standard file formats such as .jsp.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %jpress · jpress18 нояб. 2024 г.
- CVE-2022-2333036Наблюдать
A remote code execution (RCE) vulnerability in HelloWorldAddonController.java of jpress v4.2.0 allows attackers to execute arbitrary code vi
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %jpress · jpress4 февр. 2022 г.
- CVE-2021-4580635Наблюдать
jpress v4.2.0 admin panel provides a function through which attackers can modify the template and inject some malicious code.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %jpress · jpress13 янв. 2022 г.
- CVE-2021-4611435Наблюдать
jpress v 4.2.0 is vulnerable to RCE via io.jpress.module.product.ProductNotifyKit#doSendEmail.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %jpress · jpress26 янв. 2022 г.
- CVE-2021-4580835Наблюдать
jpress v4.2.0 allows users to register an account by default.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %jpress · jpress19 янв. 2022 г.
- CVE-2024-4303335Наблюдать
JPress through 5.1.1 on Windows has an arbitrary file upload vulnerability that could cause arbitrary code execution via ::$DATA to Attachme
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %jpress · jpress21 авг. 2024 г.
- CVE-2024-3235830Наблюдать
An issue in Jpress v.5.1.0 allows a remote attacker to execute arbitrary code via a crafted script to the custom plug-in module function, a
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %jpress · jpress25 апр. 2024 г.
- CVE-2024-4646830Наблюдать
A Server-Side Request Forgery (SSRF) vulnerability exists in the jpress <= v5.1.1, which can be exploited by an attacker to obtain sensitive
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %jpress · jpress11 окт. 2024 г.
- CVE-2021-4611729Наблюдать
jpress 4.2.0 is vulnerable to remote code execution via io.jpress.module.page.PageNotifyKit#doSendEmail.
ВысокаяCVSS 7,2Эксплойта нетEPSS 3 %jpress · jpress26 янв. 2022 г.
- CVE-2021-4611829Наблюдать
jpress 4.2.0 is vulnerable to remote code execution via io.jpress.module.article.kit.ArticleNotifyKit#doSendEmail.
ВысокаяCVSS 7,2Эксплойта нетEPSS 2 %jpress · jpress26 янв. 2022 г.
- CVE-2021-4611629Наблюдать
jpress 4.2.0 is vulnerable to remote code execution via io.jpress.web.admin._TemplateController#doInstall.
ВысокаяCVSS 7,2Эксплойта нетEPSS 2 %jpress · jpress26 янв. 2022 г.
- CVE-2021-4611528Наблюдать
jpress 4.2.0 is vulnerable to RCE via io.jpress.web.admin._TemplateController#doUploadFile.
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %jpress · jpress26 янв. 2022 г.
- CVE-2021-3334721Наблюдать
An issue was discovered in JPress v3.3.0 and below.
СредняяCVSS 5,4Эксплойта нетEPSS 1 %jpress · jpress18 июн. 2021 г.
- CVE-2024-1197121Наблюдать
Guizhou Xiaoma Technology jpress Avatar upload cross site scripting
СредняяCVSS 5,3Эксплойта нетEPSS 1 %jpress · jpress28 нояб. 2024 г.
- CVE-2019-627821Наблюдать
XSS exists in JPress v1.0.4 via Markdown input, or Markdown input with the code input option.
СредняяCVSS 5,4Эксплойта нетEPSS 1 %jpress · jpress14 янв. 2019 г.
- CVE-2024-1234821Наблюдать
Guizhou Xiaoma Technology jpress Attachment Upload upload AttachmentUtils.isUnSafe cross site scripting
СредняяCVSS 5,3Эксплойта нетEPSS 0 %jpress · jpress8 дек. 2024 г.
- CVE-2024-830420Наблюдать
jpress Template Module edit path traversal
СредняяCVSS 5,1Эксплойта нетEPSS 1 %jpress · jpress29 авг. 2024 г.
- CVE-2018-1917019Наблюдать
In JPress v1.0-rc.5, there is stored XSS via each of the first three input fields to the starter-tomcat-1.0/admin/setting URI, as demonstrat
СредняяCVSS 4,8Эксплойта нетEPSS 1 %jpress · jpress11 нояб. 2018 г.