Stored Cross-Site Scripting Vulnerability in Jivejdon
CVE-2026-107798
5.1MEDIUM
What is CVE-2026-107798?
The Jivejdon product is susceptible to a stored cross-site scripting (XSS) vulnerability due to the default-enabled TextStyle filter. This flaw allows authenticated attackers to inject malicious JavaScript into messages by submitting link attributes that are not properly validated. Consequently, when other users click or hover over these links, arbitrary JavaScript can be executed in their browsers, leading to potential session hijacking or defacement. Users of Jivejdon should promptly update to the secure version and review permissions to mitigate risks associated with this vulnerability.
Affected Version(s)
jivejdon 595d8d227fcdedf6f3b73540dd9f5d12dab399fe
