JFinal CMS 5.1.0 is vulnerable to SQL Injection via /admin/foldernotice/list.
- https://github.com/jflyfox/jfinal_cms/issues/51
No PoCs found on GitHub currently.