CVE-2026-48910

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
30/07/2026
Last modified:
30/07/2026

Description

A carefully crafted editing request could trigger an XSS vulnerability <br /> on Apache JSPWiki when parsing errors on the markdown renderer, which <br /> could allow the attacker to execute javascript in the victim&amp;#39;s browser <br /> and get some sensitive information about the victim.<br /> <br /> <br /> This issue affects Apache JSPWiki: through 2.12.3.<br /> <br /> Users are recommended to upgrade to version 2.12.4, which fixes the issue.