CVE-2024-45944: j2eefast

Critical severity, CVSS 9.8. EPSS: 0.9% chance of exploitation in the next 30 days.

In J2eeFAST <=2.7, the backend function has unsafe filtering, which allows an attacker to trigger certain sensitive functions resulting in arbitrary code execution.

Affected products

  • j2eefast j2eefast: before 2.6.0 (fixed in 2.6.0)

Published 2024-10-18. Last modified 2026-06-17.