CVE-2026-3292Disclosure(jizhicms / jizhicms)

LOWCVSS 8.8 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A security vulnerability has been detected in jizhiCMS up to 2.5.6. Affected is the function findAll in the library frphp/lib/Model.php of the component Batch Interface. The manipulation of the argument data leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74CWE-89

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • jizhicms

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
jizhicms

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-02-27: 3Technical Details · 2026-02-27: 302-27
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-3292 A security vulnerability has been detected in jizhiCMS up to 2.5.6. Affected is the function findAll in the library frphp/lib/Model.php of the component Batch Interface… https://www.cve.org/CVERecord?id=CVE-2026-3292

    Post summary

    A vulnerability in jizhiCMS up to version 2.5.6 affecting the findAll function in frphp/lib/Model.php has been identified, with no PoC, exploit, or patch information provided.

    00000101
    56.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-3292 SQL Injection in jizhiCMS Batch Interface via Argument Manipulation https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-3292

    Post summary

    The post announces a SQL Injection vulnerability in jizhiCMS’s batch interface and links to a vulnerability detail page.

    0000028
    4.0K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-3292 - jizhiCMS Batch Model.php findAll sql injection Intel Report: https://ift.tt/UT3CLDS

    Post summary

    A new CVE-2026-3292 vulnerability in jizhiCMS’s Batch Model.php file allows SQL injection, as reported by CYBERDUDEBIVASH Sentinel Apex.

    000002
    341 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appjizhicmsjizhicms---

Explore more