Search
Search Results (4 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-28814 | 1 Apache | 1 Jspwiki | 2026-07-31 | 7.5 High |
| Arbitrary Wiki Markup rendering due to lack of authentication in Apache JSPWiki up to 2.12.3 allows attacker to obtain sensitive data stored in JSPWiki variables. Users are recommended to upgrade to version 2.12.4 or 3.0.0, which fixes this issue. | ||||
| CVE-2026-28811 | 1 Apache | 1 Jspwiki | 2026-07-31 | 7.5 High |
| Debug Messages Revealing Unnecessary Information in Apache JSPWiki up to 2.12.3. Users are recommended to upgrade to version 2.12.4, which fixes this issue. | ||||
| CVE-2026-28812 | 1 Apache | 1 Jspwiki | 2026-07-31 | 9.8 Critical |
| UserManager lack of checks allows impersonation in Apache JSPWiki up to 2.12.3 which may allow attackers to escalate privileges. Users are recommended to upgrade to version 2.12.4 or newer which fixes this issue. | ||||
| CVE-2026-28813 | 1 Apache | 1 Jspwiki | 2026-07-31 | 8.8 High |
| Apache JSPWiki, up to 2.12.3, is vulnerable to JSON Hijacking, which leads to csrf vulnerabilities. Users are recommended to upgrade to version 2.12.4, which fixes this issue. | ||||
Page 1 of 1.