← Vulnerability feed

Vulnerability record · CVE-2026-28813 · published 30 July 2026

CVE-2026-28813: Apache jspwiki cross-site request forgery vulnerability

Apache · Jspwiki

Apache JSPWiki, up to 2.12.3, is vulnerable to JSON Hijacking, which leads to csrf vulnerabilities. Users are recommended to upgrade to version 2.12.4, which fixes this issue.

8.8 CVSS 3.1 High EPSS 0.27% · top 82.8% CWE-352 · Cross-site request forgery
8.8CVSS 3.1 base score
0.27%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
5 Aug 2026Last modified by NVD

Description

Apache JSPWiki, up to 2.12.3, is vulnerable to JSON Hijacking, which leads to csrf vulnerabilities. Users are recommended to upgrade to version 2.12.4, which fixes this issue.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-28813 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-28812Apache jspwiki authentication bypass by spoofing vulnerabilityUserManager lack of checks allows impersonation in Apache JSPWiki up to 2.12.3 which may allow attackers to escalate privileges. Users are recommende…EPSS 0.69%9.1CVE-2021-44140Apache jspwiki incorrect default permissions vulnerabilityRemote attackers may delete arbitrary files in a system hosting a JSPWiki instance, versions up to 2.11.0.M8, by using a carefuly crafted http reques…EPSS 6.4%8.8CVE-2022-34158Apache jspwiki cross-site request forgery vulnerabilityA carefully crafted invocation on the Image plugin could trigger an CSRF vulnerability on Apache JSPWiki before 2.11.3, which could allow a group pri…EPSS 1.2%8.8CVE-2022-24947Apache jspwiki cross-site request forgery vulnerabilityApache JSPWiki user preferences form is vulnerable to CSRF attacks, which can lead to account takeover. Apache JSPWiki users should upgrade to 2.11.2…EPSS 1.2%7.5CVE-2026-28814Apache jspwiki missing authentication for critical function vulnerabilityArbitrary Wiki Markup rendering due to lack of authentication in Apache JSPWiki up to 2.12.3 allows attacker to obtain sensitive data stored in JSPWi…EPSS 0.66%7.5CVE-2026-28811Apache jspwiki vulnerabilityDebug Messages Revealing Unnecessary Information in Apache JSPWiki up to 2.12.3. Users are recommended to upgrade to version 2.12.4, which fixes this…EPSS 0.79%7.5CVE-2025-24853Apache jspwiki cross-site scripting vulnerabilityA carefully crafted request when creating a header link using the wiki markup syntax, which could allow the attacker to execute javascript in the vic…EPSS 0.53%7.5CVE-2019-0225Apache jspwiki path traversal vulnerabilityA specially crafted url could be used to access files under the ROOT directory of the application on Apache JSPWiki 2.9.0 to 2.11.0.M2, which could b…EPSS 10.0%

Source: NIST National Vulnerability Database (record CVE-2026-28813), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.