Browse all 7 CVE security advisories affecting Juanpao. AI-powered Chinese analysis, POCs, and references for each vulnerability.
Juanpao is a web application primarily used for content management and e-commerce platforms. Historically, it has been susceptible to multiple remote code execution vulnerabilities, cross-site scripting flaws, and privilege escalation issues, accounting for its seven recorded CVEs. The application's security posture has been compromised through insufficient input validation and improper access controls, leading to unauthorized system access and data breaches. Notable incidents include cases where attackers leveraged RCE vulnerabilities to deploy web shells and maintain persistent access, highlighting ongoing challenges in secure coding practices and timely patch management.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2024-1264 | Juanpao JPShop UploadsController.php actionUpdate unrestricted upload — JPShopCWE-434 | 6.3 | Medium | 2024-02-06 |
| CVE-2024-1263 | Juanpao JPShop API PosterController.php actionUpdate unrestricted upload — JPShopCWE-434 | 6.3 | Medium | 2024-02-06 |
| CVE-2024-1262 | Juanpao JPShop API MaterialController.php actionUpdate unrestricted upload — JPShopCWE-434 | 6.3 | Medium | 2024-02-06 |
| CVE-2024-1261 | Juanpao JPShop API ComboController.php actionIndex unrestricted upload — JPShopCWE-434 | 6.3 | Medium | 2024-02-06 |
| CVE-2024-1260 | Juanpao JPShop API ComboController.php actionIndex unrestricted upload — JPShopCWE-434 | 6.3 | Medium | 2024-02-06 |
| CVE-2024-1259 | Juanpao JPShop API AppController.php unrestricted upload — JPShopCWE-434 | 6.3 | Medium | 2024-02-06 |
| CVE-2024-1258 | Juanpao JPShop API params.php hard-coded key — JPShopCWE-321 | 3.1 | Low | 2024-02-06 |
This page lists every published CVE security advisory associated with Juanpao. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.