CVE-2020-19151: Jflyfox Jfinal CMS

High severity, CVSS 8.8. EPSS: 5% chance of exploitation in the next 30 days.

Command Injection in Jfinal CMS v4.7.1 and earlier allows remote attackers to execute arbitrary code by uploading a malicious HTML template file via the component 'jfinal_cms/admin/filemanager/list'.

Affected products

  • Jflyfox Jfinal CMS: up to and including 4.7.1

Published 2021-09-15. Last modified 2026-06-17.