Apache Jspwiki vulnerabilities
24 known vulnerabilities affecting apache/jspwiki.
Total CVEs
24
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH4MEDIUM19
Vulnerabilities
Page 2 of 2
CVE-2019-10090P4MEDIUMCVSS 6.1≤ 2.10.5v2.11.02019-09-23
CVE-2019-10090 [MEDIUM] CWE-79 CVE-2019-10090: On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger
On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki, related to the plain editor, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim.
nvd
CVE-2025-24854P4MEDIUMCVSS 6.1fixed in 2.12.32025-07-31
CVE-2025-24854 [MEDIUM] CWE-79 CVE-2025-24854: A carefully crafted request using the Image plugin could trigger an XSS vulnerability on Apache JSP
A carefully crafted request using the Image plugin could trigger an XSS
vulnerability on Apache JSPWiki, which could allow the attacker to
execute javascript in the victim's browser and get some sensitive
information about the victim.
Apache JSPWiki users should upgrade to 2.12.3 or later.
nvd
CVE-2022-24948P4MEDIUMCVSS 6.1fixed in 2.11.22022-02-25
CVE-2022-24948 [MEDIUM] CWE-79 CVE-2022-24948: A carefully crafted user preferences for submission could trigger an XSS vulnerability on Apache JSP
A carefully crafted user preferences for submission could trigger an XSS vulnerability on Apache JSPWiki, related to the user preferences screen, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim. Apache JSPWiki users should upgrade to 2.11.2 or later.
nvd
CVE-2022-46907P4MEDIUMCVSS 6.1fixed in 2.12.02023-05-25
CVE-2022-46907 [MEDIUM] CWE-79 CVE-2022-46907: A carefully crafted request on several JSPWiki plugins could trigger an XSS vulnerability on Apache
A carefully crafted request on several JSPWiki plugins could trigger an XSS vulnerability on Apache JSPWiki, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim. Apache JSPWiki users should upgrade to 2.12.0 or later.
nvd
← Previous2 / 2