Search Results (2 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2025-50228 1 Cherry-toto 1 Jizhicms 2026-04-10 N/A
Jizhicms v2.5.4 is vulnerable to Server-Side Request Forgery (SSRF) in User Evaluation, Message, and Comment modules.
CVE-2024-34255 2 Cherry-toto, Jizhicms 2 Jizhicms, Jizhicms 2025-06-13 6.1 Medium
jizhicms v2.5.1 contains a Cross-Site Scripting(XSS) vulnerability in the message function.