← Vulnerability feed

Vulnerability record · CVE-2019-0224 · published 28 March 2019

CVE-2019-0224: Apache jspwiki cross-site scripting vulnerability

Apache · Jspwiki

In Apache JSPWiki 2.9.0 to 2.11.0.M2, a carefully crafted URL could execute javascript on another user's session. No information could be saved on the server or jspwiki database, nor would an attacker be able to execute js on someone else's browser; only on its own browser.

6.1 CVSS 3.0 Medium EPSS 5.1% · top 7.9% CWE-79 · Cross-site scripting
6.1CVSS 3.0 base score, v2 4.3
5.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
10References
17 Jun 2026Last modified by NVD

Description

In Apache JSPWiki 2.9.0 to 2.11.0.M2, a carefully crafted URL could execute javascript on another user's session. No information could be saved on the server or jspwiki database, nor would an attacker be able to execute js on someone else's browser; only on its own browser.

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-0224 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-28812Apache jspwiki authentication bypass by spoofing vulnerabilityUserManager lack of checks allows impersonation in Apache JSPWiki up to 2.12.3 which may allow attackers to escalate privileges. Users are recommende…EPSS 0.69%9.1CVE-2021-44140Apache jspwiki incorrect default permissions vulnerabilityRemote attackers may delete arbitrary files in a system hosting a JSPWiki instance, versions up to 2.11.0.M8, by using a carefuly crafted http reques…EPSS 6.4%8.8CVE-2026-28813Apache jspwiki cross-site request forgery vulnerabilityApache JSPWiki, up to 2.12.3, is vulnerable to JSON Hijacking, which leads to csrf vulnerabilities. Users are recommended to upgrade to version 2.12.…EPSS 0.27%8.8CVE-2022-34158Apache jspwiki cross-site request forgery vulnerabilityA carefully crafted invocation on the Image plugin could trigger an CSRF vulnerability on Apache JSPWiki before 2.11.3, which could allow a group pri…EPSS 1.2%8.8CVE-2022-24947Apache jspwiki cross-site request forgery vulnerabilityApache JSPWiki user preferences form is vulnerable to CSRF attacks, which can lead to account takeover. Apache JSPWiki users should upgrade to 2.11.2…EPSS 1.2%7.5CVE-2026-28814Apache jspwiki missing authentication for critical function vulnerabilityArbitrary Wiki Markup rendering due to lack of authentication in Apache JSPWiki up to 2.12.3 allows attacker to obtain sensitive data stored in JSPWi…EPSS 0.66%7.5CVE-2026-28811Apache jspwiki vulnerabilityDebug Messages Revealing Unnecessary Information in Apache JSPWiki up to 2.12.3. Users are recommended to upgrade to version 2.12.4, which fixes this…EPSS 0.79%7.5CVE-2025-24853Apache jspwiki cross-site scripting vulnerabilityA carefully crafted request when creating a header link using the wiki markup syntax, which could allow the attacker to execute javascript in the vic…EPSS 0.53%

Source: NIST National Vulnerability Database (record CVE-2019-0224), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.