Back to CVE List

CVE-2026-48910

MEDIUM SEVERITY

CVSS Score & Metrics

Base Score
6.5 / 10
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Vulnerability Description

A carefully crafted editing request could trigger an XSS vulnerability
on Apache JSPWiki when parsing errors on the markdown renderer, which
could allow the attacker to execute javascript in the victim's browser
and get some sensitive information about the victim.


This issue affects Apache JSPWiki: through 2.12.3.

Users are recommended to upgrade to version 2.12.4, which fixes the issue.

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-80
Source
NVD
Vendor
Apache Software Foundation
Product
Apache JSPWiki

External References

Discussion (0)

Add Comment

No comments yet. Be the first!