CVE-2026-48910
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
30/07/2026
Last modified:
30/07/2026
Description
A carefully crafted editing request could trigger an XSS vulnerability <br />
on Apache JSPWiki when parsing errors on the markdown renderer, which <br />
could allow the attacker to execute javascript in the victim&#39;s browser <br />
and get some sensitive information about the victim.<br />
<br />
<br />
This issue affects Apache JSPWiki: through 2.12.3.<br />
<br />
Users are recommended to upgrade to version 2.12.4, which fixes the issue.
Impact
Base Score 3.x
6.50
Severity 3.x
MEDIUM



