Apache

Jspwiki

29 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.35%
  • Veröffentlicht 30.07.2026 16:17:12
  • Zuletzt bearbeitet 05.08.2026 16:49:17

A carefully crafted editing request could trigger an XSS vulnerability on Apache JSPWiki when parsing errors on the markdown renderer, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information ...

  • EPSS 0.41%
  • Veröffentlicht 30.07.2026 16:17:11
  • Zuletzt bearbeitet 05.08.2026 16:49:44

Arbitrary Wiki Markup rendering due to lack of authentication in Apache JSPWiki up to 2.12.3 allows attacker to obtain sensitive data stored in JSPWiki variables. Users are recommended to upgrade to version 2.12.4 or 3.0.0, which fixes this issue.

  • EPSS 0.19%
  • Veröffentlicht 30.07.2026 16:17:11
  • Zuletzt bearbeitet 05.08.2026 16:50:13

Apache JSPWiki, up to 2.12.3, is vulnerable to JSON Hijacking, which leads to csrf vulnerabilities. Users are recommended to upgrade to version 2.12.4, which fixes this issue.

  • EPSS 0.4%
  • Veröffentlicht 30.07.2026 16:17:10
  • Zuletzt bearbeitet 05.08.2026 16:50:37

UserManager lack of checks allows impersonation in Apache JSPWiki up to 2.12.3 which may allow attackers to escalate privileges. Users are recommended to upgrade to version 2.12.4 or newer which fixes this issue.

  • EPSS 0.48%
  • Veröffentlicht 30.07.2026 16:17:10
  • Zuletzt bearbeitet 05.08.2026 16:51:17

Debug Messages Revealing Unnecessary Information in Apache JSPWiki up to 2.12.3. Users are recommended to upgrade to version 2.12.4, which fixes this issue.

  • EPSS 0.45%
  • Veröffentlicht 31.07.2025 08:43:18
  • Zuletzt bearbeitet 04.11.2025 22:16:07

A carefully crafted request using the Image plugin could trigger an XSS vulnerability on Apache JSPWiki, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim. Apache ...

  • EPSS 0.53%
  • Veröffentlicht 31.07.2025 08:42:06
  • Zuletzt bearbeitet 04.11.2025 22:16:07

A carefully crafted request when creating a header link using the wiki markup syntax, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim. Further research by the JSPW...

  • EPSS 59.43%
  • Veröffentlicht 24.06.2024 08:15:09
  • Zuletzt bearbeitet 20.03.2025 18:15:17

XSS in Upload page in Apache JSPWiki 2.12.1 and priors allows the attacker to execute javascript in the victim's browser and get some sensitive information about the victim. Apache JSPWiki users should upgrade to 2.12.2 or later.

  • EPSS 1.16%
  • Veröffentlicht 25.05.2023 07:15:08
  • Zuletzt bearbeitet 13.02.2025 17:15:48

A carefully crafted request on several JSPWiki plugins could trigger an XSS vulnerability on Apache JSPWiki, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim. Apache JSP...

  • EPSS 1.21%
  • Veröffentlicht 04.08.2022 07:15:07
  • Zuletzt bearbeitet 21.11.2024 07:08:58

A carefully crafted invocation on the Image plugin could trigger an CSRF vulnerability on Apache JSPWiki before 2.11.3, which could allow a group privilege escalation of the attacker's account. Further examination of this issue established that it co...