Apache Jspwiki vulnerabilities
29 known vulnerabilities affecting apache/jspwiki.
Total CVEs
29
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH7MEDIUM20
Vulnerabilities
Page 2 of 2
CVE-2019-10077P4MEDIUMCVSS 6.1≥ 2.9.0, ≤ 2.11.0v2.11.02019-05-20
CVE-2019-10077 [MEDIUM] CWE-79 CVE-2019-10077: A carefully crafted InterWiki link could trigger an XSS vulnerability on Apache JSPWiki 2.9.0 to 2.1
A carefully crafted InterWiki link could trigger an XSS vulnerability on Apache JSPWiki 2.9.0 to 2.11.0.M3, which could lead to session hijacking.
nvd
CVE-2019-10087P4MEDIUMCVSS 6.1≤ 2.10.5v2.11.02019-09-23
CVE-2019-10087 [MEDIUM] CWE-79 CVE-2019-10087: On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger
On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki, related to the Page Revision History, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim.
nvd
CVE-2019-12407P4MEDIUMCVSS 6.1≤ 2.10.5v2.11.02019-09-23
CVE-2019-12407 [MEDIUM] CWE-79 CVE-2019-12407: On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger
On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki, related to the remember parameter on some of the JSPs, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim.
nvd
CVE-2019-12404P4MEDIUMCVSS 6.1≤ 2.10.5v2.11.02019-09-23
CVE-2019-12404 [MEDIUM] CWE-79 CVE-2019-12404: On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger
On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki, related to InfoContent.jsp, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim.
nvd
CVE-2019-10089P4MEDIUMCVSS 6.1≤ 2.10.5v2.11.02019-09-23
CVE-2019-10089 [MEDIUM] CWE-79 CVE-2019-10089: On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger
On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki, related to the WYSIWYG editor, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim.
nvd
CVE-2019-10090P4MEDIUMCVSS 6.1≤ 2.10.5v2.11.02019-09-23
CVE-2019-10090 [MEDIUM] CWE-79 CVE-2019-10090: On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger
On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki, related to the plain editor, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim.
nvd
CVE-2022-24948P4MEDIUMCVSS 6.1fixed in 2.11.22022-02-25
CVE-2022-24948 [MEDIUM] CWE-79 CVE-2022-24948: A carefully crafted user preferences for submission could trigger an XSS vulnerability on Apache JSP
A carefully crafted user preferences for submission could trigger an XSS vulnerability on Apache JSPWiki, related to the user preferences screen, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim. Apache JSPWiki users should upgrade to 2.11.2 or later.
nvd
CVE-2022-46907P4MEDIUMCVSS 6.1fixed in 2.12.02023-05-25
CVE-2022-46907 [MEDIUM] CWE-79 CVE-2022-46907: A carefully crafted request on several JSPWiki plugins could trigger an XSS vulnerability on Apache
A carefully crafted request on several JSPWiki plugins could trigger an XSS vulnerability on Apache JSPWiki, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim. Apache JSPWiki users should upgrade to 2.12.0 or later.
nvd
CVE-2025-24854P4MEDIUMCVSS 6.1fixed in 2.12.32025-07-31
CVE-2025-24854 [MEDIUM] CWE-79 CVE-2025-24854: A carefully crafted request using the Image plugin could trigger an XSS vulnerability on Apache JSP
A carefully crafted request using the Image plugin could trigger an XSS
vulnerability on Apache JSPWiki, which could allow the attacker to
execute javascript in the victim's browser and get some sensitive
information about the victim.
Apache JSPWiki users should upgrade to 2.12.3 or later.
nvd
← Previous2 / 2