oss-sec mailing list archives
CVE-2026-48910: Apache JSPWiki: Markdown parser allows XSS injection in Markdown error processing
From: Juan Pablo Santos Rodríguez <juanpablo () apache org>
Date: Thu, 30 Jul 2026 14:14:53 +0200
Severity Moderate Vendor The Apache Software Foundation Versions Affected Apache JSPWiki up to 2.12.3 Description A carefully crafted editing request could trigger an XSS vulnerability on Apache JSPWiki when parsing errors on the markdown renderer, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim. Mitigation Apache JSPWiki users should upgrade to 2.12.4 or later. Credit The issue was discovered by Justin Ng from Cyver Security Agency of Singapore / Inland Reveue Authority of Singapore References https://jspwiki-wiki.apache.org/Wiki.jsp?page=CVE-2026-48910 https://www.cve.org/CVERecord?id=CVE-2026-48910
Current thread:
- CVE-2026-48910: Apache JSPWiki: Markdown parser allows XSS injection in Markdown error processing Juan Pablo Santos Rodríguez (Jul 30)
