CVE-2026-107801 — Jivejdon through 5.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to execute JavaScript by uploading at…
Description
Jivejdon through 5.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to execute JavaScript by uploading attachments with an attacker-supplied Content-Type. Attackers can upload a file declared as text/html, which UploadShowAction serves inline, and share its link to run JavaScript on the application's origin for viewing users.
CVSS v4.0 base metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XMedium severity
Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.
AV
Network
Attack Vector
AC
Low
Attack Complexity
AT
None
Attack Requirements
PR
Low
Privileges Required
UI
Passive
User Interaction
VC
Low
Confidentiality (Vulnerable System)
VI
Low
Integrity (Vulnerable System)
VA
None
Availability (Vulnerable System)
SC
Low
Confidentiality (Subsequent System)
SI
Low
Integrity (Subsequent System)
SA
None
Availability (Subsequent System)
References
- advisory[email protected]https://github.com/banq/jivejdon
- advisory[email protected]https://github.com/banq/jivejdon/blob/ee67a65e65228644a71c8317d7e34deea50f95ef/src/main/java/com/jdon/jivejdon/domain/model/message/upload/UploadHelper.java#L84-L91
- advisory[email protected]https://github.com/banq/jivejdon/blob/ee67a65e65228644a71c8317d7e34deea50f95ef/src/main/java/com/jdon/jivejdon/presentation/action/UploadShowAction.java#L135-L142
- advisory[email protected]https://github.com/banq/jivejdon/issues/28
- advisory[email protected]https://www.vulncheck.com/advisories/jivejdon-through-5.0-stored-xss-via-attachment-upload-content-type
Related threats
same CWE or vendorCVE-2026-107800 — Jivejdon through 5.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject script into private short m…
CVE-2026-107800 · 1h ago
CVE-2026-107799 — Jivejdon through 5.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject script by posting unsanitiz…
CVE-2026-107799 · 1h ago
CVE-2026-107798 — jivejdon from commit 595d8d22 through commit ee67a65e contains a stored cross-site scripting vulnerability in the default-enabled TextStyle filter …
CVE-2026-107798 · 1h ago
CVE-2026-107797 — Jivejdon through 5.0 contains a reflected cross-site scripting vulnerability in application/message/postThread.jsp that allows attackers to inject …
CVE-2026-107797 · 1h ago
CVE-2026-107796 — Jivejdon from commit 5489372d through commit ee67a65e contains a reflected cross-site scripting vulnerability in application/query/taggedThreadList…
CVE-2026-107796 · 1h ago
CVE-2026-105269 — Satel Netco Design versions prior to v2.1.7 contains a stored cross site scripting vulnerability.
CVE-2026-105269 · 1h ago