Status: UPDATED | Advisory ID: CVE-2026-28813
| CVE | CVE-2026-28813 |
| CVSS | CVSS 8.8 (High). |
| Affected products | Apache jspwiki |
| Classified as | CWE-352 (Cross-Site Request Forgery (CSRF)) |
Apache JSPWiki, up to 2.12.3, is vulnerable to JSON Hijacking, which leads to csrf vulnerabilities.
Users are recommended to upgrade to version 2.12.4, which fixes this issue.
| Source | Reference |
|---|---|
| NVD | https://nvd.nist.gov/vuln/detail/CVE-2026-28813 |
| Vendor advisory | https://lists.apache.org/thread/56440mymwkxt1hf3j8hjpo41yco7gotv |