Vulnerabilities > Apache > Jspwiki > 1.8.2

DATE CVE VULNERABILITY TITLE RISK
2021-11-24 CVE-2021-44140 Incorrect Default Permissions vulnerability in Apache Jspwiki
Remote attackers may delete arbitrary files in a system hosting a JSPWiki instance, versions up to 2.11.0.M8, by using a carefuly crafted http request on logout, given that those files are reachable to the user running the JSPWiki instance.
network
low complexity
apache CWE-276
critical
9.1
2019-09-23 CVE-2019-12407 Cross-site Scripting vulnerability in Apache Jspwiki
On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki, related to the remember parameter on some of the JSPs, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim.
network
low complexity
apache CWE-79
6.1
2019-09-23 CVE-2019-10090 Cross-site Scripting vulnerability in Apache Jspwiki
On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki, related to the plain editor, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim.
network
low complexity
apache CWE-79
6.1
2019-09-23 CVE-2019-12404 Cross-site Scripting vulnerability in Apache Jspwiki
On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki, related to InfoContent.jsp, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim.
network
low complexity
apache CWE-79
6.1
2019-09-23 CVE-2019-10089 Cross-site Scripting vulnerability in Apache Jspwiki
On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki, related to the WYSIWYG editor, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim.
network
low complexity
apache CWE-79
6.1
2019-09-23 CVE-2019-10087 Cross-site Scripting vulnerability in Apache Jspwiki
On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki, related to the Page Revision History, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim.
network
low complexity
apache CWE-79
6.1
2019-02-11 CVE-2018-20242 Cross-site Scripting vulnerability in Apache Jspwiki
A carefully crafted URL could trigger an XSS vulnerability on Apache JSPWiki, from versions up to 2.10.5, which could lead to session hijacking.
network
low complexity
apache CWE-79
6.1