CVE-2026-28813
Severity CVSS v4.0:
Pending analysis
Type:
CWE-352
Cross-Site Request Forgery (CSRF)
Publication date:
30/07/2026
Last modified:
31/07/2026
Description
Apache JSPWiki, up to 2.12.3, is vulnerable to JSON Hijacking, which leads to csrf vulnerabilities.<br />
Users are recommended to upgrade to version 2.12.4, which fixes this issue.
Impact
Base Score 3.x
8.80
Severity 3.x
HIGH



