Severity Moderate Vendor The Apache Software Foundation
Versions Affected Apache JSPWiki up to 2.12.3 Description Apache JSPWiki is vulnerable to JSON Hijacking, which leads to csrf vulnerabilities. Mitigation Apache JSPWiki users should upgrade to 2.12.4 or later. Credit The issue was discovered by Janne Jalkannen from Apache JSPWiki References https://jspwiki-wiki.apache.org/Wiki.jsp?page=CVE-2026-28813 https://www.cve.org/CVERecord?id=CVE-2026-28813
