A carefully crafted editing request could trigger an XSS vulnerability
on Apache JSPWiki when parsing errors on the markdown renderer, which
could allow the attacker to execute javascript in the victim's browser
and get some sensitive information about the victim.
This issue affects Apache JSPWiki: through 2.12.3.
Users are recommended to upgrade to version 2.12.4, which fixes the issue.
Metrics
Affected Vendors & Products
References
History
Thu, 30 Jul 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache jspwiki |
|
| Vendors & Products |
Apache
Apache jspwiki |
Thu, 30 Jul 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Thu, 30 Jul 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A carefully crafted editing request could trigger an XSS vulnerability on Apache JSPWiki when parsing errors on the markdown renderer, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim. This issue affects Apache JSPWiki: through 2.12.3. Users are recommended to upgrade to version 2.12.4, which fixes the issue. | |
| Title | Apache JSPWiki: Markdown parser allows XSS injection in Markdown error processing | |
| Weaknesses | CWE-80 | |
| References |
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2026-07-30T16:37:15.693Z
Reserved: 2026-05-26T10:41:07.254Z
Link: CVE-2026-48910
Updated: 2026-07-30T16:37:15.693Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-30T18:00:15Z