Apache JSPWiki, up to 2.12.3, is vulnerable to JSON Hijacking, which leads to csrf vulnerabilities.
Users are recommended to upgrade to version 2.12.4, which fixes this issue.
Users are recommended to upgrade to version 2.12.4, which fixes this issue.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 31 Jul 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Thu, 30 Jul 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache jspwiki |
|
| Vendors & Products |
Apache
Apache jspwiki |
Thu, 30 Jul 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Apache JSPWiki, up to 2.12.3, is vulnerable to JSON Hijacking, which leads to csrf vulnerabilities. Users are recommended to upgrade to version 2.12.4, which fixes this issue. | |
| Title | Apache JSPWiki: JSPWiki vulnerable to JSON hijacking | |
| Weaknesses | CWE-352 | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2026-07-31T11:34:33.218Z
Reserved: 2026-03-03T15:01:42.672Z
Link: CVE-2026-28813
Updated: 2026-07-30T16:36:34.389Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-31T19:45:03Z
Weaknesses