cjbi has 4 CVEs on record. 4 were published in the last 90 days. The busiest recent month was September 2026 with 4. The median CVSS is 6.8 (medium).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.8
- Publish → KEV
- —
- Last 90 days
- 4 prev 0
Worst active — by depth score
CVE-2026-92918High· 8.8admin3 through 3.0.0 persists user session tokens in the audit log event body when publishing UserLoggedIn domain events60CVE-2026-92919High· 8.1admin3 through 3.0.0 fails to sanitize client-supplied filenames in the upload handler, allowing authenticated users to write files outside the storage root on Windows deployments57CVE-2026-92921Medium· 4.9admin3 through 3.0.0 stores account passwords using single-round MD5 with only the username as salt and no key derivation function39CVE-2026-92920Medium· 5.4admin3 through 3.0.0 fails to invalidate existing sessions when disabling a user account, allowing attackers to retain authenticated access with original permissions30
cjbi vulnerabilities
CVEs affecting cjbi, newest first. Open any entry for full detail, references, and exploit status.
4 CVEsRSS
CVE-2026-92921Medium· 4.9PoCadmin3 through 3.0.0 stores account passwords using single-round MD5 with only the username as salt and no key derivation function
admin3 through 3.0.0 stores account passwords using single-round MD5 with only the username as salt and no key derivation function. Attackers with database access can recover plaintext passwords through offline dictionary or brute-force …
CVE-2026-92920Medium· 5.4admin3 through 3.0.0 fails to invalidate existing sessions when disabling a user account, allowing attackers to retain authenticated access with original permissions
admin3 through 3.0.0 fails to invalidate existing sessions when disabling a user account, allowing attackers to retain authenticated access with original permissions. Attackers can continue using bearer tokens issued before account disab…
CVE-2026-92919High· 8.1PoCadmin3 through 3.0.0 fails to sanitize client-supplied filenames in the upload handler, allowing authenticated users to write files outside the storage root on Windows deployments
admin3 through 3.0.0 fails to sanitize client-supplied filenames in the upload handler, allowing authenticated users to write files outside the storage root on Windows deployments. Attackers can use dot-dot path segments in filenames to …
CVE-2026-92918High· 8.8PoCadmin3 through 3.0.0 persists user session tokens in the audit log event body when publishing UserLoggedIn domain events
admin3 through 3.0.0 persists user session tokens in the audit log event body when publishing UserLoggedIn domain events. Attackers with log:view permission can read the JSON response from the GET /logs endpoint to harvest session tokens…