CVE-2026-107796 — Jivejdon from commit 5489372d through commit ee67a65e contains a reflected cross-site scripting vulnerability in application/query/taggedThreadList…
Description
Jivejdon from commit 5489372d through commit ee67a65e contains a reflected cross-site scripting vulnerability in application/query/taggedThreadList.jsp that allows unauthenticated attackers to inject script via unencoded tagID and count parameters. Attackers can craft a link with a script-closing payload in tagID or count, triggered when start exceeds zero, to execute JavaScript in victims' browsers.
CVSS v4.0 base metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XMedium severity
Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.
AV
Network
Attack Vector
AC
Low
Attack Complexity
AT
None
Attack Requirements
PR
None
Privileges Required
UI
Passive
User Interaction
VC
Low
Confidentiality (Vulnerable System)
VI
Low
Integrity (Vulnerable System)
VA
None
Availability (Vulnerable System)
SC
Low
Confidentiality (Subsequent System)
SI
Low
Integrity (Subsequent System)
SA
None
Availability (Subsequent System)
References
- advisory[email protected]https://github.com/banq/jivejdon
- advisory[email protected]https://github.com/banq/jivejdon/blob/ee67a65e65228644a71c8317d7e34deea50f95ef/application/query/taggedThreadList.jsp#L25-L41
- advisory[email protected]https://github.com/banq/jivejdon/issues/28
- advisory[email protected]https://www.vulncheck.com/advisories/jivejdon-through-commit-ee67a65e-reflected-xss-via-taggedthreadlist-jsp-tagid-and-count-parameters
Related threats
same CWE or vendorCVE-2026-107801 — Jivejdon through 5.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to execute JavaScript by uploading at…
CVE-2026-107801 · 1h ago
CVE-2026-107800 — Jivejdon through 5.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject script into private short m…
CVE-2026-107800 · 1h ago
CVE-2026-107799 — Jivejdon through 5.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject script by posting unsanitiz…
CVE-2026-107799 · 1h ago
CVE-2026-107798 — jivejdon from commit 595d8d22 through commit ee67a65e contains a stored cross-site scripting vulnerability in the default-enabled TextStyle filter …
CVE-2026-107798 · 1h ago
CVE-2026-107797 — Jivejdon through 5.0 contains a reflected cross-site scripting vulnerability in application/message/postThread.jsp that allows attackers to inject …
CVE-2026-107797 · 1h ago
CVE-2026-105269 — Satel Netco Design versions prior to v2.1.7 contains a stored cross site scripting vulnerability.
CVE-2026-105269 · 1h ago