Medium severity5.4NVD Advisory· Published Oct 8, 2026
CVE-2026-107799
CVE-2026-107799
Description
Jivejdon through 5.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject script by posting unsanitized forum message bodies. Message bodies are rendered by messageListBody.jsp with filter="false" and non-escaping default filters, executing script in the browser of every user viewing the thread.
Affected products
1Patches
Vulnerability mechanics
References
4- github.com/banq/jivejdon/blob/ee67a65e65228644a71c8317d7e34deea50f95ef/application/thread/messageListBody.jspnvd
- github.com/banq/jivejdon/blob/ee67a65e65228644a71c8317d7e34deea50f95ef/src/main/java/com/jdon/jivejdon/domain/model/message/output/RenderingFilterManagerImp.javanvd
- github.com/banq/jivejdon/issues/28nvd
- www.vulncheck.com/advisories/jivejdon-through-5.0-stored-xss-via-messagelistbody-jsp-forum-message-renderingnvd
News mentions
0No linked articles in our index yet.