CVE-2025-24854: Apache JSPWiki: Cross-Site Scripting (XSS) in JSPWiki Image plugin

2025-07-30 Thread Juan Pablo Santos Rodríguez
Severity: Medium Affected versions: - Apache JSPWiki before Apache JSPWiki up to 2.12.2 Description: A carefully crafted request using the Image plugin could trigger an XSS vulnerability on Apache JSPWiki, which could allow the attacker to execute javascript in the victim's browser and get som

CVE-2025-24853: Apache JSPWiki: Cross-Site Scripting (XSS) in JSPWiki Header Link processing

2025-07-30 Thread Juan Pablo Santos Rodríguez
Severity: Medium Affected versions: - Apache JSPWiki before Apache JSPWiki up to 2.12.2 Description: A carefully crafted request when creating a header link using the wiki markup syntax, which could allow the attacker to execute javascript in the victim's browser and get some sensitive inform

[ANNOUNCE] Apache JSPWiki 2.12.3 released

2025-07-30 Thread Juan Pablo Santos Rodríguez
The Apache JSPWiki team is pleased to announce the release of JSPWiki 2.12.3. This is the fourth release on the 2.12 series of Apache JSPWiki, a feature-rich and extensible WikiWiki engine built around the standard JEE components. The release is available here: https://jspwiki-wiki.apache.org/Wik