VYPR
Medium severity6.1NVD Advisory· Published Oct 8, 2026

CVE-2026-107796

CVE-2026-107796

Description

Jivejdon from commit 5489372d through commit ee67a65e contains a reflected cross-site scripting vulnerability in application/query/taggedThreadList.jsp that allows unauthenticated attackers to inject script via unencoded tagID and count parameters. Attackers can craft a link with a script-closing payload in tagID or count, triggered when start exceeds zero, to execute JavaScript in victims' browsers.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Banq/Jivejdonllm-fuzzy
    Range: commit 5489372d through commit ee67a65e
  • Range: commit 5489372d through commit ee67a65e

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.