Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-48910

Gravedad CVSS v3.1:
MEDIA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
30/07/2026
Última modificación:
30/07/2026

Descripción

*** Pendiente de traducción *** A carefully crafted editing request could trigger an XSS vulnerability <br /> on Apache JSPWiki when parsing errors on the markdown renderer, which <br /> could allow the attacker to execute javascript in the victim&amp;#39;s browser <br /> and get some sensitive information about the victim.<br /> <br /> <br /> This issue affects Apache JSPWiki: through 2.12.3.<br /> <br /> Users are recommended to upgrade to version 2.12.4, which fixes the issue.