Skip to main content

Vendor/product archive

apache / jspwiki CVEs

Beta · best-effort

29 CVEs tagged to apache / jspwiki2 Critical, 7 High, 20 Medium, 0 Low, 0 Unrated.

CVE-2019-10076

Published May 20, 2019

A carefully crafted malicious attachment could trigger an XSS vulnerability on Apache JSPWiki 2.9.0 to 2.11.0.M3, which could lead to session hijacking.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-0225

Published Mar 28, 2019

A specially crafted url could be used to access files under the ROOT directory of the application on Apache JSPWiki 2.9.0 to 2.11.0.M2, which could be used by an attacker to obtai…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-0224

Published Mar 28, 2019

In Apache JSPWiki 2.9.0 to 2.11.0.M2, a carefully crafted URL could execute javascript on another user's session. No information could be saved on the server or jspwiki database,…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-20242

Published Feb 11, 2019

A carefully crafted URL could trigger an XSS vulnerability on Apache JSPWiki, from versions up to 2.10.5, which could lead to session hijacking.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 26-29 of 29 CVEsPage 2 of 2