on Apache JSPWiki when parsing errors on the markdown renderer, which
could allow the attacker to execute javascript in the victim's browser
and get some sensitive information about the victim.
This issue affects Apache JSPWiki: through 2.12.3.
Users are recommended to upgrade to version 2.12.4, which fixes the issue.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 30 Jul 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache jspwiki |
|
| Vendors & Products |
Apache
Apache jspwiki |
Thu, 30 Jul 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Thu, 30 Jul 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A carefully crafted editing request could trigger an XSS vulnerability on Apache JSPWiki when parsing errors on the markdown renderer, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim. This issue affects Apache JSPWiki: through 2.12.3. Users are recommended to upgrade to version 2.12.4, which fixes the issue. | |
| Title | Apache JSPWiki: Markdown parser allows XSS injection in Markdown error processing | |
| Weaknesses | CWE-80 | |
| References |
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2026-07-30T16:37:15.693Z
Reserved: 2026-05-26T10:41:07.254Z
Link: CVE-2026-48910
Updated: 2026-07-30T16:37:15.693Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-30T18:00:15Z
-
CWE-80
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)