Known vulnerabilities in Apache JSPWiki 2.12.3
Vendor:
Apache Foundation
Software:
Apache JSPWiki
Version:
2.12.3
Software CPE:
cpe:2.3:a:apache_foundation:jspwiki:*:*:*:*:*:*:*:*
Website:
https://www.apache.org
Total vulnerabilities:
5
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
8.8
Vulnerabilities by Severity
2.12.4
3.0.0
2.12.5
2.14.2
2.12.3
2.12.2
2.12.1
2.12.0
2.11.3
2.11.2
2.11.1
2.11.0M8
2.11.0M7
2.11.0M6
2.11.0
2.11.0.M5
2.11.0.M4
2.11.0.M3
2.11.0.M2
2.11.0.M1
2.10.5
2.10.4
2.10.3
2.10.2
2.10.1
2.10.0
2.9.1
2.9.0
2.8.4
2.8.3
2.8.2
2.8.1
2.8.0
2.6.4
2.6.3
2.6.2
2.6.1
2.6.0
2.5.139
2.4.104
2.4.103
2.5.139-beta
2.1.121
2.1.122
2.1.120
Vulnerabilities (5)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU145180 - Information Exposure Through an Error Message CVE-2026-28811 |
CWE-209 | Medium | 2.12.4 | 25.08.2026 |
SB2026082557 |
||
| #VU145179 - Improper Access Control CVE-2026-28812 |
CWE-284 | Low | 2.12.4 | 25.08.2026 |
SB2026082557 |
||
| #VU145178 - Insufficient Verification of Data Authenticity CVE-2026-28813 |
CWE-345 | Medium | 2.12.4 | 25.08.2026 |
SB2026082557 |
||
| #VU145177 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2026-48910 |
CWE-79 | Low | 2.12.4 | 25.08.2026 |
SB2026082557 |
||
| #VU145176 - Missing Authentication for Critical Function CVE-2026-28814 |
CWE-306 | Medium | 2.12.4 | 25.08.2026 |
SB2026082557 |