CVE-2026-28813

Severity CVSS v4.0:
Pending analysis
Type:
CWE-352 Cross-Site Request Forgery (CSRF)
Publication date:
30/07/2026
Last modified:
31/07/2026

Description

Apache JSPWiki, up to 2.12.3, is vulnerable to JSON Hijacking, which leads to csrf vulnerabilities.<br /> Users are recommended to upgrade to version 2.12.4, which fixes this issue.