← All Advisories

CVE-2026-28813

Status: UPDATED  |  Advisory ID: CVE-2026-28813

Key Details

CVECVE-2026-28813
CVSSCVSS 8.8 (High).
Affected productsApache jspwiki
Classified asCWE-352 (Cross-Site Request Forgery (CSRF))

What to Know

Apache JSPWiki, up to 2.12.3, is vulnerable to JSON Hijacking, which leads to csrf vulnerabilities.

Users are recommended to upgrade to version 2.12.4, which fixes this issue.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-28813
Vendor advisoryhttps://lists.apache.org/thread/56440mymwkxt1hf3j8hjpo41yco7gotv