CVE-2021-46116
jpress
jpress 4.2.0 is vulnerable to remote code execution via io.jpress.web.admin._TemplateController#doInstall. The admin panel provides a function through which attackers can install templates and inject some malicious code.
- CVSS
- 7.2
- EPSS
- 2.13% 80.2% percentile
- CISA KEV
- Not listed
- Published
- 2022.01.27