Back to database
Schedule53Medium5.3VulnerabilityCVE-2026-107797No patch link observed

CVE-2026-107797 — Jivejdon through 5.0 contains a reflected cross-site scripting vulnerability in application/message/postThread.jsp that allows attackers to inject …

Published Oct 8, 2026, 10:17 PM UTCIngested 37m agoSource NVD(cve-db)CVE-2026-107797

Description

Jivejdon through 5.0 contains a reflected cross-site scripting vulnerability in application/message/postThread.jsp that allows attackers to inject script via the to and tag parameters. Attackers can send crafted links to authenticated users, breaking out of unencoded inline JavaScript string literals to execute arbitrary JavaScript in the victim's session.

CVSS v4.0 base metrics

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
5.3

Medium severity

Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.

AV

Network

Attack Vector

AC

Low

Attack Complexity

AT

None

Attack Requirements

PR

None

Privileges Required

UI

Passive

User Interaction

VC

Low

Confidentiality (Vulnerable System)

VI

Low

Integrity (Vulnerable System)

VA

None

Availability (Vulnerable System)

SC

Low

Confidentiality (Subsequent System)

SI

Low

Integrity (Subsequent System)

SA

None

Availability (Subsequent System)