Back to database
Schedule53Medium5.3VulnerabilityCVE-2026-107796No patch link observed

CVE-2026-107796 — Jivejdon from commit 5489372d through commit ee67a65e contains a reflected cross-site scripting vulnerability in application/query/taggedThreadList…

Published Oct 8, 2026, 10:17 PM UTCIngested 38m agoSource NVD(cve-db)CVE-2026-107796

Description

Jivejdon from commit 5489372d through commit ee67a65e contains a reflected cross-site scripting vulnerability in application/query/taggedThreadList.jsp that allows unauthenticated attackers to inject script via unencoded tagID and count parameters. Attackers can craft a link with a script-closing payload in tagID or count, triggered when start exceeds zero, to execute JavaScript in victims' browsers.

CVSS v4.0 base metrics

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
5.3

Medium severity

Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.

AV

Network

Attack Vector

AC

Low

Attack Complexity

AT

None

Attack Requirements

PR

None

Privileges Required

UI

Passive

User Interaction

VC

Low

Confidentiality (Vulnerable System)

VI

Low

Integrity (Vulnerable System)

VA

None

Availability (Vulnerable System)

SC

Low

Confidentiality (Subsequent System)

SI

Low

Integrity (Subsequent System)

SA

None

Availability (Subsequent System)