CVE-2024-45944: j2eefast
Critical severity, CVSS 9.8. EPSS: 0.9% chance of exploitation in the next 30 days.
In J2eeFAST <=2.7, the backend function has unsafe filtering, which allows an attacker to trigger certain sensitive functions resulting in arbitrary code execution.
Affected products
- j2eefast j2eefast: before 2.6.0 (fixed in 2.6.0)
Published 2024-10-18. Last modified 2026-06-17.