CVE-2026-107798 — jivejdon from commit 595d8d22 through commit ee67a65e contains a stored cross-site scripting vulnerability in the default-enabled TextStyle filter …
Description
jivejdon from commit 595d8d22 through commit ee67a65e contains a stored cross-site scripting vulnerability in the default-enabled TextStyle filter that inserts unvalidated URLs into anchor href attributes. Authenticated attackers can post messages with javascript: links or quote-breaking URLs to execute JavaScript when other users click or hover over rendered links.
CVSS v4.0 base metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XMedium severity
Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.
AV
Network
Attack Vector
AC
Low
Attack Complexity
AT
None
Attack Requirements
PR
Low
Privileges Required
UI
Passive
User Interaction
VC
Low
Confidentiality (Vulnerable System)
VI
Low
Integrity (Vulnerable System)
VA
None
Availability (Vulnerable System)
SC
Low
Confidentiality (Subsequent System)
SI
Low
Integrity (Subsequent System)
SA
None
Availability (Subsequent System)
References
- advisory[email protected]https://github.com/banq/jivejdon
- advisory[email protected]https://github.com/banq/jivejdon/blob/ee67a65e65228644a71c8317d7e34deea50f95ef/src/main/java/com/jdon/jivejdon/domain/model/message/output/html/TextStyle.java#L242-L243
- advisory[email protected]https://github.com/banq/jivejdon/issues/28
- advisory[email protected]https://www.vulncheck.com/advisories/jivejdon-through-commit-ee67a65e-stored-xss-via-markdown-links-in-textstyle-rendering-filter
Related threats
same CWE or vendorCVE-2026-107801 — Jivejdon through 5.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to execute JavaScript by uploading at…
CVE-2026-107801 · 1h ago
CVE-2026-107800 — Jivejdon through 5.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject script into private short m…
CVE-2026-107800 · 1h ago
CVE-2026-107799 — Jivejdon through 5.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject script by posting unsanitiz…
CVE-2026-107799 · 1h ago
CVE-2026-107797 — Jivejdon through 5.0 contains a reflected cross-site scripting vulnerability in application/message/postThread.jsp that allows attackers to inject …
CVE-2026-107797 · 1h ago
CVE-2026-107796 — Jivejdon from commit 5489372d through commit ee67a65e contains a reflected cross-site scripting vulnerability in application/query/taggedThreadList…
CVE-2026-107796 · 1h ago
CVE-2026-105269 — Satel Netco Design versions prior to v2.1.7 contains a stored cross site scripting vulnerability.
CVE-2026-105269 · 1h ago