VendorsApachejspwikiany version
Vulnerabilities

Apache JSPWiki any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

29CVEs
CVE-2026-28812
Apache JSPWiki: UserManager does not sanity-check user database at startup
Published 2026-07-30 · Analyzed
9.8EPSS 0.004
CVE-2021-44140
Arbitrary file deletion on logout
Published 2021-11-24 · Modified
9.1EPSS 0.064
CVE-2022-34158
User Group Privilege Escalation
Published 2022-08-04 · Modified
8.8EPSS 0.012
CVE-2022-24947
Apache JSPWiki CSRF Account Takeover
Published 2022-02-25 · Modified
8.8EPSS 0.012
CVE-2026-28813
Apache JSPWiki: JSPWiki vulnerable to JSON hijacking
Published 2026-07-30 · Analyzed
8.8EPSS 0.002
CVE-2019-0225
A specially crafted url could be used to access files under the ROOT directory of the application on Apache JSPWiki 2.9.0 to 2.11.0.M2, which could be used by an attacker to obtain registered users' details.
Published 2019-03-28 · Modified
7.8EPSS 0.103
CVE-2025-24853
Apache JSPWiki: Cross-Site Scripting (XSS) in JSPWiki Header Link processing
Published 2025-07-31 · Modified
7.5EPSS 0.005
CVE-2026-28811
Apache JSPWiki: Error Handling - Reveals Error Details
Published 2026-07-30 · Analyzed
7.5EPSS 0.005
CVE-2026-28814
Apache JSPWiki: Pre-Authentication Arbitrary Wiki Markup Rendering
Published 2026-07-30 · Analyzed
7.5EPSS 0.004
CVE-2022-28731
Apache JSPWiki CSRF in UserPreferences.jsp
Published 2022-08-04 · Modified
6.5EPSS 0.569
CVE-2026-48910
Apache JSPWiki: Markdown parser allows XSS injection in Markdown error processing
Published 2026-07-30 · Analyzed
6.5EPSS 0.003
CVE-2022-28730
Apache JSPWiki Cross-site scripting vulnerability on AJAXPreview.jsp
Published 2022-08-04 · Modified
6.1EPSS 0.854
CVE-2022-27166
XSS vulnerability on XHRHtml2Markup.jsp in JSPWiki 2.11.2
Published 2022-08-04 · Modified
6.1EPSS 0.854
CVE-2022-28732
Apache JSPWiki Cross-site scripting vulnerability on WeblogPlugin
Published 2022-08-04 · Modified
6.1EPSS 0.820
CVE-2024-27136
Apache JSPWiki: Cross-site scripting vulnerability on upload page
Published 2024-06-24 · Modified
6.1EPSS 0.608
CVE-2018-20242
A carefully crafted URL could trigger an XSS vulnerability on Apache JSPWiki, from versions up to 2.10.5, which could lead to session hijacking.
Published 2019-02-11 · Modified
6.1EPSS 0.054
CVE-2019-0224
In Apache JSPWiki 2.9.0 to 2.11.0.M2, a carefully crafted URL could execute javascript on another user's session. No information could be saved on the server or jspwiki database, nor would an attacker be able to execute js on someone else's browser; only on its own browser.
Published 2019-03-28 · Modified
6.1EPSS 0.052
CVE-2019-10078
A carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki 2.9.0 to 2.11.0.M3, which could lead to session hijacking. Initial reporting indicated ReferredPagesPlugin, but further analysis showed that multiple plugins were vulnerable.
Published 2019-05-20 · Modified
6.1EPSS 0.049
CVE-2019-10076
A carefully crafted malicious attachment could trigger an XSS vulnerability on Apache JSPWiki 2.9.0 to 2.11.0.M3, which could lead to session hijacking.
Published 2019-05-20 · Modified
6.1EPSS 0.047
CVE-2019-10077
A carefully crafted InterWiki link could trigger an XSS vulnerability on Apache JSPWiki 2.9.0 to 2.11.0.M3, which could lead to session hijacking.
Published 2019-05-20 · Modified
6.1EPSS 0.047
CVE-2021-40369
XSS vulnerability on Denounce plugin
Published 2021-11-24 · Modified
6.1EPSS 0.034
CVE-2019-12407
On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki, related to the remember parameter on some of the JSPs, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim.
Published 2019-09-23 · Modified
6.1EPSS 0.029
CVE-2019-12404
On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki, related to InfoContent.jsp, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim.
Published 2019-09-23 · Modified
6.1EPSS 0.029
CVE-2019-10087
On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki, related to the Page Revision History, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim.
Published 2019-09-23 · Modified
6.1EPSS 0.029
CVE-2019-10089
On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki, related to the WYSIWYG editor, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim.
Published 2019-09-23 · Modified
6.1EPSS 0.029
CVE-2019-10090
On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki, related to the plain editor, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim.
Published 2019-09-23 · Modified
6.1EPSS 0.029
CVE-2022-24948
Apache JSPWiki Cross-site scripting vulnerability on User Preferences screen
Published 2022-02-25 · Modified
6.1EPSS 0.023
CVE-2022-46907
Apache JSPWiki: XSS Injection points in several plugins
Published 2023-05-25 · Modified
6.1EPSS 0.012
CVE-2025-24854
Apache JSPWiki: Cross-Site Scripting (XSS) in JSPWiki Image plugin
Published 2025-07-31 · Modified
6.1EPSS 0.004