Vulnerabilities > Apache > Jspwiki > High

DATE CVE VULNERABILITY TITLE RISK
2022-08-04 CVE-2022-34158 Cross-Site Request Forgery (CSRF) vulnerability in Apache Jspwiki
A carefully crafted invocation on the Image plugin could trigger an CSRF vulnerability on Apache JSPWiki before 2.11.3, which could allow a group privilege escalation of the attacker's account.
network
low complexity
apache CWE-352
8.8
2022-02-25 CVE-2022-24947 Cross-Site Request Forgery (CSRF) vulnerability in Apache Jspwiki
Apache JSPWiki user preferences form is vulnerable to CSRF attacks, which can lead to account takeover.
network
low complexity
apache CWE-352
8.8
2019-03-28 CVE-2019-0225 Path Traversal vulnerability in Apache Jspwiki 2.11.0
A specially crafted url could be used to access files under the ROOT directory of the application on Apache JSPWiki 2.9.0 to 2.11.0.M2, which could be used by an attacker to obtain registered users' details.
network
low complexity
apache CWE-22
7.5