XSS Vulnerability in Apache JSPWiki Affects Multiple Versions
CVE-2026-48910
6.5MEDIUM
What is CVE-2026-48910?
A vulnerability exists in Apache JSPWiki where an attacker can exploit the markdown renderer by submitting a maliciously crafted editing request. This can lead to a Cross-Site Scripting (XSS) issue, allowing the execution of arbitrary JavaScript code in the victim's browser. Consequently, sensitive information about the victim may be compromised. Users are advised to upgrade to version 2.12.4, which addresses this security flaw.
Affected Version(s)
Apache JSPWiki 0 <= 2.12.3
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Justin Ng from Cyver Security Agency of Singapore / Inland Reveue Authority of Singapore