What is CVE-2026-48910?
CVE-2026-48910 is a stored XSS vulnerability in Apache JSPWiki. A crafted editing request can trigger XSS via parse errors in the markdown renderer, allowing JavaScript execution in the victim's browser. Users should immediately upgrade to the latest Apache JSPWiki version or apply the official security patch.
Azərbaycanca: CVE-2026-48910 Apache JSPWiki-də saxlanılan XSS zəifliyidir. Xüsusi hazırlanmış redaktə sorğusu markdown renderer-də parse xətaları zamanı XSS-ə səbəb olur. İstifadəçilər dərhal Apache JSPWiki-ni ən son versiyaya yeniləməli və ya rəsmi kanallardan təhlükəsizlik yaması tətbiq etməlidir.
Related CVEs
link basis: same weakness class CWE-79; shared vendor: Apache
FAQ2
What can an attacker achieve by exploiting CVE-2026-48910?
An attacker can perform stored XSS by crafting a malicious editing request that triggers parse errors in the markdown renderer of Apache JSPWiki, leading to JavaScript execution in the victim's browser.
What should Apache JSPWiki users do to protect against CVE-2026-48910?
Users should immediately upgrade to the latest Apache JSPWiki version or apply the official security patch.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.