CVE-2026-107831 — Jivejdon through 5.0 contains a cross-site request forgery vulnerability that allows remote attackers to perform state-changing actions by abusing …
Description
Jivejdon through 5.0 contains a cross-site request forgery vulnerability that allows remote attackers to perform state-changing actions by abusing GET endpoints lacking anti-CSRF tokens. Attackers can lure authenticated users to crafted links targeting /account/protected/delAll, /account/protected/sub/delSub, or /message/updateAction to delete private messages and subscriptions or rename threads.
CVSS v4.0 base metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XMedium severity
Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.
AV
Network
Attack Vector
AC
Low
Attack Complexity
AT
None
Attack Requirements
PR
None
Privileges Required
UI
Passive
User Interaction
VC
None
Confidentiality (Vulnerable System)
VI
Low
Integrity (Vulnerable System)
VA
None
Availability (Vulnerable System)
SC
None
Confidentiality (Subsequent System)
SI
None
Integrity (Subsequent System)
SA
None
Availability (Subsequent System)
References
- advisory[email protected]https://github.com/banq/jivejdon
- advisory[email protected]https://github.com/banq/jivejdon/blob/ee67a65e65228644a71c8317d7e34deea50f95ef/application/WEB-INF/struts-config-shortmessage.xml#L112-L118
- advisory[email protected]https://github.com/banq/jivejdon/blob/ee67a65e65228644a71c8317d7e34deea50f95ef/application/WEB-INF/struts-config-subscription.xml#L75-L79
- advisory[email protected]https://github.com/banq/jivejdon/blob/ee67a65e65228644a71c8317d7e34deea50f95ef/src/main/java/com/jdon/jivejdon/presentation/action/message/UpdateThreadNameAction.java#L19-L36
- advisory[email protected]https://github.com/banq/jivejdon/issues/28
- advisory[email protected]https://www.vulncheck.com/advisories/jivejdon-through-5.0-csrf-via-get-based-account-and-thread-actions
Related threats
same CWE or vendorCVE-2026-78388 — IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 is vulnerable to cross-site request forgery whi…
CVE-2026-78388 · 6h ago
CVE-2026-107337 — The Malcolm kiosk Flask application exposes a POST /script_call/<script> endpoint with zero authentication and wildcard CORS (CORS(app)).
CVE-2026-107337 · 9h ago
CVE-2026-107295 — Pydantic AI is a Python agent framework for building applications and workflows with Generative AI.
CVE-2026-107295 · 10h ago
CVE-2026-66479 — Cross-Site Request Forgery (CSRF) vulnerability in Liquid Web / StellarWP WPComplete wpcomplete allows Stored XSS.This issue affects WPComplete: fr…
CVE-2026-66479 · 14h ago
CVE-2026-62142 — Cross-Site Request Forgery (CSRF) vulnerability in Melapress WP 2FA wp-2fa allows Cross Site Request Forgery.This issue affects WP 2FA: from n/a th…
CVE-2026-62142 · 14h ago
CVE-2026-106611 — Cross-Site Request Forgery (CSRF) vulnerability in WPMU DEV Forminator forminator allows Cross Site Request Forgery.This issue affects Forminator: …
CVE-2026-106611 · 14h ago