Vulnerabilities
Vulnerable Software
Apache:  >> Jspwiki  >> 2.11.3  Security Vulnerabilities
A carefully crafted request using the Image plugin could trigger an XSS vulnerability on Apache JSPWiki, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim. Apache JSPWiki users should upgrade to 2.12.3 or later.
CVSS Score
6.1
EPSS Score
0.003
Published
2025-07-31
A carefully crafted request when creating a header link using the wiki markup syntax, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim. Further research by the JSPWiki team showed that the markdown parser allowed this kind of attack too. Apache JSPWiki users should upgrade to 2.12.3 or later.
CVSS Score
7.5
EPSS Score
0.003
Published
2025-07-31
XSS in Upload page in Apache JSPWiki 2.12.1 and priors allows the attacker to execute javascript in the victim's browser and get some sensitive information about the victim. Apache JSPWiki users should upgrade to 2.12.2 or later.
CVSS Score
6.1
EPSS Score
0.293
Published
2024-06-24
A carefully crafted request on several JSPWiki plugins could trigger an XSS vulnerability on Apache JSPWiki, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim. Apache JSPWiki users should upgrade to 2.12.0 or later.
CVSS Score
6.1
EPSS Score
0.037
Published
2023-05-25


Contact Us

Shodan ® - All rights reserved