ZeroHour

Vulnerabilities

6 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2020-21729
JEECMS x1.1 contains a stored cross-site scripting (XSS) vulnerability in the component of /member-vipcenter.htm, which allows attackers to execute arbitrary we

JEECMS x1.1 contains a stored cross-site scripting (XSS) vulnerability in the component of /member-vipcenter.htm, which allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

NVD description · AI analysis pending
5.4<1% PoC
  • jeecms jeecms x
CVE-2020-20799
JeeCMS 1.0.1 contains a stored cross-site scripting (XSS) vulnerability which allows attackers to execute arbitrary web scripts or HTML via a crafted payload in

JeeCMS 1.0.1 contains a stored cross-site scripting (XSS) vulnerability which allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the commentText parameter.

NVD description · AI analysis pending
5.4<1% PoC
  • jeecms jeecms
CVE-2018-20528
JEECMS 9 has SSRF via the ueditor/getRemoteImage.jspx upfile parameter.

JEECMS 9 has SSRF via the ueditor/getRemoteImage.jspx upfile parameter.

NVD description · AI analysis pending
6.51%
  • jeecms jeecms
CVE-2018-19545
+1 in the same advisory: …19544
JEECMS 9.3 has CSRF via the api/admin/role/save URI to add a user.

JEECMS 9.3 has CSRF via the api/admin/role/save URI to add a user.

NVD description · AI analysis pending
8.8
group max
<1% PoC
  • jeecms jeecms
CVE-2018-18952
JEECMS 9.3 has XSS via an index.do#/content/update?type=update URI.

JEECMS 9.3 has XSS via an index.do#/content/update?type=update URI.

NVD description · AI analysis pending
4.8<1% PoC
  • jeecms jeecms