XSS Vulnerability in Apache JSPWiki Affects Multiple Versions
CVE-2026-48910

6.5MEDIUM

Key Information:

Vendor

Apache

Vendor
CVE Published:
30 July 2026

What is CVE-2026-48910?

A vulnerability exists in Apache JSPWiki where an attacker can exploit the markdown renderer by submitting a maliciously crafted editing request. This can lead to a Cross-Site Scripting (XSS) issue, allowing the execution of arbitrary JavaScript code in the victim's browser. Consequently, sensitive information about the victim may be compromised. Users are advised to upgrade to version 2.12.4, which addresses this security flaw.

Affected Version(s)

Apache JSPWiki 0 <= 2.12.3

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Justin Ng from Cyver Security Agency of Singapore / Inland Reveue Authority of Singapore
.