CVE-2026-48910

A carefully crafted editing request could trigger an XSS vulnerability on Apache JSPWiki when parsing errors on the markdown renderer, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim. This issue affects Apache JSPWiki: through 2.12.3. Users are recommended to upgrade to version 2.12.4, which fixes the issue.
References
Link Resource
https://lists.apache.org/thread/yvbdjnocw5qq3xkbjs9h77ghlg0bsw2c Mailing List Vendor Advisory
http://www.openwall.com/lists/oss-security/2026/07/30/18 Mailing List Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:apache:jspwiki:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-07-30 16:17

Updated : 2026-08-05 16:49


NVD link : CVE-2026-48910

Mitre link : CVE-2026-48910

CVE.ORG link : CVE-2026-48910


JSON object : View

Products Affected

apache

  • jspwiki
CWE
CWE-80

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)