Severity Moderate Vendor The Apache Software Foundation
Versions Affected Apache JSPWiki up to 2.12.3 Description A carefully crafted editing request could trigger an XSS vulnerability on Apache JSPWiki when parsing errors on the markdown renderer, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim. Mitigation Apache JSPWiki users should upgrade to 2.12.4 or later. Credit The issue was discovered by Justin Ng from Cyver Security Agency of Singapore / Inland Reveue Authority of Singapore References https://jspwiki-wiki.apache.org/Wiki.jsp?page=CVE-2026-48910 https://www.cve.org/CVERecord?id=CVE-2026-48910
