A carefully crafted editing request could trigger an XSS vulnerability
on Apache JSPWiki when parsing errors on the markdown renderer, which
could allow the attacker to execute javascript in the victim's browser
and get some sensitive information about the victim.
This issue affects Apache JSPWiki: through 2.12.3.
Users are recommended to upgrade to version 2.12.4, which fixes the issue.
References
| Link | Resource |
|---|---|
| https://lists.apache.org/thread/yvbdjnocw5qq3xkbjs9h77ghlg0bsw2c | Mailing List Vendor Advisory |
| http://www.openwall.com/lists/oss-security/2026/07/30/18 | Mailing List Third Party Advisory |
Configurations
History
No history.
Information
Published : 2026-07-30 16:17
Updated : 2026-08-05 16:49
NVD link : CVE-2026-48910
Mitre link : CVE-2026-48910
CVE.ORG link : CVE-2026-48910
JSON object : View
Products Affected
apache
- jspwiki
CWE
CWE-80
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
