{"api_version":"1","generated_at":"2026-07-30T20:38:17+00:00","cve":"CVE-2026-48910","urls":{"html":"https://cve.report/CVE-2026-48910","api":"https://cve.report/api/cve/CVE-2026-48910.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-48910","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-48910"},"summary":{"title":"Apache JSPWiki: Markdown parser allows XSS injection in Markdown error processing","description":"A carefully crafted editing request could trigger an XSS vulnerability \non Apache JSPWiki when parsing errors on the markdown renderer, which \ncould allow the attacker to execute javascript in the victim's browser \nand get some sensitive information about the victim.\n\n\nThis issue affects Apache JSPWiki: through 2.12.3.\n\nUsers are recommended to upgrade to version 2.12.4, which fixes the issue.","state":"PUBLISHED","assigner":"apache","published_at":"2026-07-30 16:17:12","updated_at":"2026-07-30 19:33:40"},"problem_types":["CWE-80","CWE-80 CWE-80 Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)"],"metrics":[{"version":"3.1","source":"ADP","type":"DECLARED","score":"6.5","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","data":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM","confidentialityImpact":"HIGH","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","version":"3.1"}},{"version":"3.1","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","score":"6.5","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.openwall.com/lists/oss-security/2026/07/30/18","name":"http://www.openwall.com/lists/oss-security/2026/07/30/18","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://lists.apache.org/thread/yvbdjnocw5qq3xkbjs9h77ghlg0bsw2c","name":"https://lists.apache.org/thread/yvbdjnocw5qq3xkbjs9h77ghlg0bsw2c","refsource":"security@apache.org","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-48910","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-48910","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Apache Software Foundation","product":"Apache JSPWiki","version":"affected 2.12.3 semver","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Justin Ng from Cyver Security Agency of Singapore / Inland Reveue Authority of Singapore","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM","confidentialityImpact":"HIGH","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","version":"3.1"}},{"other":{"content":{"id":"CVE-2026-48910","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2026-07-30T16:36:48.479198Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-07-30T16:36:52.080Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"},{"providerMetadata":{"dateUpdated":"2026-07-30T16:37:15.693Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"url":"http://www.openwall.com/lists/oss-security/2026/07/30/18"}],"title":"CVE Program Container"}],"cna":{"affected":[{"defaultStatus":"unaffected","product":"Apache JSPWiki","vendor":"Apache Software Foundation","versions":[{"lessThanOrEqual":"2.12.3","status":"affected","version":"0","versionType":"semver"}]}],"credits":[{"lang":"en","type":"finder","value":"Justin Ng from Cyver Security Agency of Singapore / Inland Reveue Authority of Singapore"}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>A carefully crafted editing request could trigger an XSS vulnerability \non Apache JSPWiki when parsing errors on the markdown renderer, which \ncould allow the attacker to execute javascript in the victim's browser \nand get some sensitive information about the victim.\n</p><p>This issue affects Apache JSPWiki: through 2.12.3.</p><p>Users are recommended to upgrade to version 2.12.4, which fixes the issue.</p>"}],"value":"A carefully crafted editing request could trigger an XSS vulnerability \non Apache JSPWiki when parsing errors on the markdown renderer, which \ncould allow the attacker to execute javascript in the victim's browser \nand get some sensitive information about the victim.\n\n\nThis issue affects Apache JSPWiki: through 2.12.3.\n\nUsers are recommended to upgrade to version 2.12.4, which fixes the issue."}],"metrics":[{"other":{"content":{"text":"moderate"},"type":"Textual description of severity"}}],"problemTypes":[{"descriptions":[{"cweId":"CWE-80","description":"CWE-80 Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-07-30T15:56:33.613Z","orgId":"f0158376-9dc2-43b6-827c-5f631a4d8d09","shortName":"apache"},"references":[{"tags":["vendor-advisory"],"url":"https://lists.apache.org/thread/yvbdjnocw5qq3xkbjs9h77ghlg0bsw2c"}],"source":{"discovery":"UNKNOWN"},"title":"Apache JSPWiki: Markdown parser allows XSS injection in Markdown error processing","x_generator":{"engine":"Vulnogram 0.2.0"}}},"cveMetadata":{"assignerOrgId":"f0158376-9dc2-43b6-827c-5f631a4d8d09","assignerShortName":"apache","cveId":"CVE-2026-48910","datePublished":"2026-07-30T15:56:33.613Z","dateReserved":"2026-05-26T10:41:07.254Z","dateUpdated":"2026-07-30T16:37:15.693Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-07-30 16:17:12","lastModifiedDate":"2026-07-30 19:33:40","problem_types":["CWE-80","CWE-80 CWE-80 Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)"],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-30T16:36:48.479198Z","id":"CVE-2026-48910","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"48910","Ordinal":"1","Title":"Apache JSPWiki: Markdown parser allows XSS injection in Markdown","CVE":"CVE-2026-48910","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"48910","Ordinal":"1","NoteData":"A carefully crafted editing request could trigger an XSS vulnerability \non Apache JSPWiki when parsing errors on the markdown renderer, which \ncould allow the attacker to execute javascript in the victim's browser \nand get some sensitive information about the victim.\n\n\nThis issue affects Apache JSPWiki: through 2.12.3.\n\nUsers are recommended to upgrade to version 2.12.4, which fixes the issue.","Type":"Description","Title":"Apache JSPWiki: Markdown parser allows XSS injection in Markdown"}]}}}