Back to database
Schedule51Medium5.1VulnerabilityCVE-2026-107801No patch link observed

CVE-2026-107801 — Jivejdon through 5.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to execute JavaScript by uploading at…

Published Oct 8, 2026, 10:17 PM UTCIngested 38m agoSource NVD(cve-db)CVE-2026-107801

Description

Jivejdon through 5.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to execute JavaScript by uploading attachments with an attacker-supplied Content-Type. Attackers can upload a file declared as text/html, which UploadShowAction serves inline, and share its link to run JavaScript on the application's origin for viewing users.

CVSS v4.0 base metrics

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
5.1

Medium severity

Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.

AV

Network

Attack Vector

AC

Low

Attack Complexity

AT

None

Attack Requirements

PR

Low

Privileges Required

UI

Passive

User Interaction

VC

Low

Confidentiality (Vulnerable System)

VI

Low

Integrity (Vulnerable System)

VA

None

Availability (Vulnerable System)

SC

Low

Confidentiality (Subsequent System)

SI

Low

Integrity (Subsequent System)

SA

None

Availability (Subsequent System)