CVE-2025-70397: Jizhicms

High severity, CVSS 7.2. EPSS: 0.3% chance of exploitation in the next 30 days.

jizhicms 2.5.6 is vulnerable to SQL Injection in Article/deleteAll and Extmolds/deleteAll via the data parameter.

Affected products

Published 2026-02-17. Last modified 2026-07-05.