← Vulnerability feed

Vulnerability record · CVE-2022-28730 · published 4 August 2022

CVE-2022-28730: Apache JSPWiki AJAXPreview.jsp reflected XSS via Denounce plugin

Apache · Jspwiki

Apache JSPWiki's AJAXPreview.jsp renders user-supplied URLs through the Denounce plugin without adequate sanitisation, allowing reflected cross-site scripting. The flaw is an incomplete fix for CVE-2021-40369, so sites that applied that earlier patch remain exposed. It matters because an attacker can run script in a victim's browser session and read sensitive information from the page.

6.1 CVSS 3.1 Medium EPSS 85% · top 0.3% CWE-79 · Cross-site scripting
6.1CVSS 3.1 base score
85%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

A carefully crafted request on AJAXPreview.jsp could trigger an XSS vulnerability on Apache JSPWiki, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim. This vulnerability leverages CVE-2021-40369, where the Denounce plugin dangerously renders user-supplied URLs. Upon re-testing CVE-2021-40369, it appears that the patch was incomplete as it was still possible to insert malicious input via the Denounce plugin. Apache JSPWiki users should upgrade to 2.11.3 or later.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityThe flaw is a network-reachable XSS with a very high EPSS score, though it requires user interaction and no KEV listing or confirmed public exploit is present.

What it is

Apache JSPWiki's AJAXPreview.jsp renders user-supplied URLs through the Denounce plugin without adequate sanitisation, allowing reflected cross-site scripting. The flaw is an incomplete fix for CVE-2021-40369, so sites that applied that earlier patch remain exposed. It matters because an attacker can run script in a victim's browser session and read sensitive information from the page.

Impact

An attacker can execute JavaScript in a victim's browser in the context of the JSPWiki site, exposing session data and other sensitive information visible to that user. The CVSS scope change (S:C) means the impact can extend beyond the vulnerable component.

Attack surface

Reached over the network through a crafted request to AJAXPreview.jsp; the vector shows no privileges required (PR:N) but user interaction is required (UI:R), so a victim must follow a crafted link or otherwise trigger the request.

Exploitation

Not listed in CISA KEV, but EPSS is very high (0.854, 99.7th percentile), indicating substantial predicted exploitation activity. The only references are vendor advisories, so no public exploit code is confirmed by this record.

What to do

  • Upgrade Apache JSPWiki to 2.11.3 or later, which the vendor states resolves the incomplete Denounce plugin fix.
  • If immediate upgrade is not possible, restrict or disable the Denounce plugin and review any custom URL-rendering paths.
  • Apply output encoding and URL sanitisation to all user-supplied input rendered by JSPWiki plugins.
  • Deploy a WAF rule or CSP that blocks inline script execution on JSPWiki pages as a compensating control.

Detection

  • Inspect web logs for requests to AJAXPreview.jsp containing script tags, event handlers, or javascript: URIs in parameters.
  • Monitor for reflected payloads in HTTP responses from JSPWiki endpoints and alert on unencoded script content.
  • Review browser or proxy telemetry for outbound requests or cookie access originating from JSPWiki pages shortly after a crafted link is opened.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-28730 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-28812Apache jspwiki authentication bypass by spoofing vulnerabilityUserManager lack of checks allows impersonation in Apache JSPWiki up to 2.12.3 which may allow attackers to escalate privileges. Users are recommende…EPSS 0.69%9.1CVE-2021-44140Apache jspwiki incorrect default permissions vulnerabilityRemote attackers may delete arbitrary files in a system hosting a JSPWiki instance, versions up to 2.11.0.M8, by using a carefuly crafted http reques…EPSS 6.4%8.8CVE-2026-28813Apache jspwiki cross-site request forgery vulnerabilityApache JSPWiki, up to 2.12.3, is vulnerable to JSON Hijacking, which leads to csrf vulnerabilities. Users are recommended to upgrade to version 2.12.…EPSS 0.27%8.8CVE-2022-34158Apache jspwiki cross-site request forgery vulnerabilityA carefully crafted invocation on the Image plugin could trigger an CSRF vulnerability on Apache JSPWiki before 2.11.3, which could allow a group pri…EPSS 1.2%8.8CVE-2022-24947Apache jspwiki cross-site request forgery vulnerabilityApache JSPWiki user preferences form is vulnerable to CSRF attacks, which can lead to account takeover. Apache JSPWiki users should upgrade to 2.11.2…EPSS 1.2%7.5CVE-2026-28814Apache jspwiki missing authentication for critical function vulnerabilityArbitrary Wiki Markup rendering due to lack of authentication in Apache JSPWiki up to 2.12.3 allows attacker to obtain sensitive data stored in JSPWi…EPSS 0.66%7.5CVE-2026-28811Apache jspwiki vulnerabilityDebug Messages Revealing Unnecessary Information in Apache JSPWiki up to 2.12.3. Users are recommended to upgrade to version 2.12.4, which fixes this…EPSS 0.79%7.5CVE-2025-24853Apache jspwiki cross-site scripting vulnerabilityA carefully crafted request when creating a header link using the wiki markup syntax, which could allow the attacker to execute javascript in the vic…EPSS 0.53%

Source: NIST National Vulnerability Database (record CVE-2022-28730), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.