Stored Cross-Site Scripting Vulnerability in Jivejdon Forum Product
CVE-2026-107799

5.1MEDIUM

Key Information:

Vendor

Banq

Status
Vendor
CVE Published:
8 October 2026

What is CVE-2026-107799?

Jivejdon versions up to 5.0 exhibit a stored Cross-Site Scripting (XSS) vulnerability, allowing authenticated attackers to inject malicious scripts into forum message bodies. This vulnerability arises because the message bodies are rendered unsanitized through messageListBody.jsp with filter settings that do not escape potentially harmful content. When a user views a thread containing these messages, the injected scripts are executed in their browser, posing serious security risks for all users participating in the forum.

Affected Version(s)

jivejdon 0 <= 5.0

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ikram-4
.