Cross-site scripting in Apache JSPWiki - CVE-2026-48910
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary javascript in the victim's browser and disclose sensitive information.
The vulnerability exists due to cross-site scripting in the markdown renderer error processing when handling a crafted editing request. A remote user can send a specially crafted editing request to execute arbitrary javascript in the victim's browser and disclose sensitive information.