İçeriğe atla
Noroxi

jpress kayıtları

jpress üreticisine ait 19 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
3
Düzeltme kaydı olan
%0
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

19 kayıt
  • CVE-2021-45807
    40Planlayın

    jpress v4.2.0 is vulnerable to command execution via io.jpress.web.admin._AddonController::doUploadAndInstall.

    KritikCVSS 9,8İstismar yokEPSS %2

    jpress · jpress13 Oca 2022

  • CVE-2024-50919
    39İzleyin

    Jpress until v5.1.1 has arbitrary file uploads on the windows platform, and the construction of non-standard file formats such as .jsp.

    KritikCVSS 9,8İstismar yokEPSS %1

    jpress · jpress18 Kas 2024

  • CVE-2022-23330
    36İzleyin

    A remote code execution (RCE) vulnerability in HelloWorldAddonController.java of jpress v4.2.0 allows attackers to execute arbitrary code vi

    YüksekCVSS 8,8İstismar yokEPSS %2

    jpress · jpress4 Şub 2022

  • CVE-2021-45806
    35İzleyin

    jpress v4.2.0 admin panel provides a function through which attackers can modify the template and inject some malicious code.

    YüksekCVSS 8,8İstismar yokEPSS %1

    jpress · jpress13 Oca 2022

  • CVE-2021-46114
    35İzleyin

    jpress v 4.2.0 is vulnerable to RCE via io.jpress.module.product.ProductNotifyKit#doSendEmail.

    YüksekCVSS 8,8İstismar yokEPSS %1

    jpress · jpress26 Oca 2022

  • CVE-2021-45808
    35İzleyin

    jpress v4.2.0 allows users to register an account by default.

    YüksekCVSS 8,8İstismar yokEPSS %1

    jpress · jpress19 Oca 2022

  • CVE-2024-43033
    35İzleyin

    JPress through 5.1.1 on Windows has an arbitrary file upload vulnerability that could cause arbitrary code execution via ::$DATA to Attachme

    YüksekCVSS 8,8İstismar yokEPSS %1

    jpress · jpress21 Ağu 2024

  • CVE-2024-32358
    30İzleyin

    An issue in Jpress v.5.1.0 allows a remote attacker to execute arbitrary code via a crafted script to the custom plug-in module function, a

    YüksekCVSS 7,5İstismar yokEPSS %1

    jpress · jpress25 Nis 2024

  • CVE-2024-46468
    30İzleyin

    A Server-Side Request Forgery (SSRF) vulnerability exists in the jpress <= v5.1.1, which can be exploited by an attacker to obtain sensitive

    YüksekCVSS 7,5İstismar yokEPSS %0

    jpress · jpress11 Eki 2024

  • CVE-2021-46117
    29İzleyin

    jpress 4.2.0 is vulnerable to remote code execution via io.jpress.module.page.PageNotifyKit#doSendEmail.

    YüksekCVSS 7,2İstismar yokEPSS %3

    jpress · jpress26 Oca 2022

  • CVE-2021-46118
    29İzleyin

    jpress 4.2.0 is vulnerable to remote code execution via io.jpress.module.article.kit.ArticleNotifyKit#doSendEmail.

    YüksekCVSS 7,2İstismar yokEPSS %2

    jpress · jpress26 Oca 2022

  • CVE-2021-46116
    29İzleyin

    jpress 4.2.0 is vulnerable to remote code execution via io.jpress.web.admin._TemplateController#doInstall.

    YüksekCVSS 7,2İstismar yokEPSS %2

    jpress · jpress26 Oca 2022

  • CVE-2021-46115
    28İzleyin

    jpress 4.2.0 is vulnerable to RCE via io.jpress.web.admin._TemplateController#doUploadFile.

    YüksekCVSS 7,2İstismar yokEPSS %1

    jpress · jpress26 Oca 2022

  • CVE-2021-33347
    21İzleyin

    An issue was discovered in JPress v3.3.0 and below.

    OrtaCVSS 5,4İstismar yokEPSS %1

    jpress · jpress18 Haz 2021

  • CVE-2024-11971
    21İzleyin

    Guizhou Xiaoma Technology jpress Avatar upload cross site scripting

    OrtaCVSS 5,3İstismar yokEPSS %1

    jpress · jpress28 Kas 2024

  • CVE-2019-6278
    21İzleyin

    XSS exists in JPress v1.0.4 via Markdown input, or Markdown input with the code input option.

    OrtaCVSS 5,4İstismar yokEPSS %1

    jpress · jpress14 Oca 2019

  • CVE-2024-12348
    21İzleyin

    Guizhou Xiaoma Technology jpress Attachment Upload upload AttachmentUtils.isUnSafe cross site scripting

    OrtaCVSS 5,3İstismar yokEPSS %0

    jpress · jpress8 Ara 2024

  • CVE-2024-8304
    20İzleyin

    jpress Template Module edit path traversal

    OrtaCVSS 5,1İstismar yokEPSS %1

    jpress · jpress29 Ağu 2024

  • CVE-2018-19170
    19İzleyin

    In JPress v1.0-rc.5, there is stored XSS via each of the first three input fields to the starter-tomcat-1.0/admin/setting URI, as demonstrat

    OrtaCVSS 4,8İstismar yokEPSS %1

    jpress · jpress11 Kas 2018