Vulnerabilities > Apache > Jspwiki

DATE CVE VULNERABILITY TITLE RISK
2024-06-24 CVE-2024-27136 Cross-site Scripting vulnerability in Apache Jspwiki
XSS in Upload page in Apache JSPWiki 2.12.1 and priors allows the attacker to execute javascript in the victim's browser and get some sensitive information about the victim.
network
low complexity
apache CWE-79
6.1
2023-05-25 CVE-2022-46907 Cross-site Scripting vulnerability in Apache Jspwiki
A carefully crafted request on several JSPWiki plugins could trigger an XSS vulnerability on Apache JSPWiki, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim.
network
low complexity
apache CWE-79
6.1
2022-08-04 CVE-2022-27166 Cross-site Scripting vulnerability in Apache Jspwiki
A carefully crafted request on XHRHtml2Markup.jsp could trigger an XSS vulnerability on Apache JSPWiki up to and including 2.11.2, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim.
network
low complexity
apache CWE-79
6.1
2022-08-04 CVE-2022-28730 Cross-site Scripting vulnerability in Apache Jspwiki
A carefully crafted request on AJAXPreview.jsp could trigger an XSS vulnerability on Apache JSPWiki, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim.
network
low complexity
apache CWE-79
6.1
2022-08-04 CVE-2022-28731 Cross-Site Request Forgery (CSRF) vulnerability in Apache Jspwiki
A carefully crafted request on UserPreferences.jsp could trigger an CSRF vulnerability on Apache JSPWiki before 2.11.3, which could allow the attacker to modify the email associated with the attacked account, and then a reset password request from the login page.
network
low complexity
apache CWE-352
6.5
2022-08-04 CVE-2022-28732 Cross-site Scripting vulnerability in Apache Jspwiki
A carefully crafted request on WeblogPlugin could trigger an XSS vulnerability on Apache JSPWiki, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim.
network
low complexity
apache CWE-79
6.1
2022-08-04 CVE-2022-34158 Cross-Site Request Forgery (CSRF) vulnerability in Apache Jspwiki
A carefully crafted invocation on the Image plugin could trigger an CSRF vulnerability on Apache JSPWiki before 2.11.3, which could allow a group privilege escalation of the attacker's account.
network
low complexity
apache CWE-352
8.8
2022-02-25 CVE-2022-24947 Cross-Site Request Forgery (CSRF) vulnerability in Apache Jspwiki
Apache JSPWiki user preferences form is vulnerable to CSRF attacks, which can lead to account takeover.
network
low complexity
apache CWE-352
8.8
2022-02-25 CVE-2022-24948 Cross-site Scripting vulnerability in Apache Jspwiki
A carefully crafted user preferences for submission could trigger an XSS vulnerability on Apache JSPWiki, related to the user preferences screen, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim.
network
low complexity
apache CWE-79
6.1
2021-11-24 CVE-2021-40369 Cross-site Scripting vulnerability in Apache Jspwiki
A carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki, related to the Denounce plugin, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim.
network
low complexity
apache CWE-79
6.1