CVE-2026-28813

CVE-2026-28813: Apache JSPWiki: JSPWiki vulnerable to JSON hijacking

Vendor Apache Software Foundation
Product Apache JSPWiki
Weakness CWE-352 · CSRF
Published July 30, 2026
Last update July 31, 2026

CVSS base score

What the vulnerability does

01Description

Apache JSPWiki, up to 2.12.3, is vulnerable to JSON Hijacking, which leads to csrf vulnerabilities. Users are recommended to upgrade to version 2.12.4, which fixes this issue.

Key dates

02Disclosure timeline

July 30, 2026 CVE published
July 31, 2026 Record updated

Related vulnerabilities

04Related CVE