Vulnerabilities in cjbi
8 resultsVexday analysis
O fornecedor cjbi apresenta um risco contido com apenas 4 vulnerabilidades catalogadas e nenhuma sob exploração ativa conhecida. Não há vulnerabilidades críticas ou recentes registradas, mas a fraqueza dominante é CWE-74 (Improper Neutralization of Special Elements), indicando potencial para injections — recomenda-se monitorar futuras descobertas nesta classe de falha.
CVE-2024-12482MEDIUMcjbi wetech-cms Database Backup BackupFileUtil.java backup path traversalEPSS 1.0%CVE-2024-12479MEDIUMcjbi wetech-cms TopicDao.java searchTopicByKeyword sql injectionEPSS 0.6%CVE-2024-12481MEDIUMcjbi wetech-cms UserDao.java findUser sql injectionEPSS 0.6%CVE-2024-12480MEDIUMcjbi wetech-cms TopicDao.java searchTopic sql injectionEPSS 0.6%CVE-2026-92919HIGHadmin3 through 3.0.0 Arbitrary File Write via Path Traversal in Storage Upload FilenameEPSS 0.4%CVE-2026-92918HIGHadmin3 through 3.0.0 Session Token Disclosure via Audit LogEPSS 0.4%CVE-2026-92920MEDIUMadmin3 through 3.0.0 Session Not Invalidated When a User Account Is DisabledEPSS 0.2%CVE-2026-92921MEDIUMadmin3 through 3.0.0 Weak Password Hashing via Single-Round MD5EPSS 0.2%