Weak Password Storage in Jivejdon Up to Version 5.0
CVE-2026-107829

8.2HIGH

Key Information:

Vendor

Banq

Status
Vendor
CVE Published:
8 October 2026

What is CVE-2026-107829?

Jivejdon, up to version 5.0, suffers from a vulnerability due to the insecure storage of account passwords, utilizing unsalted MD5 hashes. This method of password storage exposes users to significant risks; if attackers gain access to the user table through database exploitation or SQL injection attacks, they can leverage precomputed tables or GPU attacks to crack passwords easily, compromising user accounts and sensitive information.

Affected Version(s)

jivejdon 0 <= 5.0

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ikram-4
.