-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stems from unsanitized user input in the 'keyword' field during blog publication and improper output encoding when rendering the stored data. While no explicit code is provided, JFinal CMS's structure suggests:
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| com.jfinal:jfinal | maven | <= 5.1.0 |
Ongoing coverage of React2Shell