Jspwiki
Vendor:
First CVE: Feb 11, 2019 · Active for 7 years
24
Total CVEs
More Total CVEs than 95% of tracked products
4.0
Avg CVEs / Year
Higher CVE frequency than 83% of tracked products
6.6
Avg CVSS
Higher Avg CVSS than 32% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Jspwiki over time
Volume of CVEsAvg CVSS Base Score
First CVE
Feb 11, 2019
7 years ago
Most Recent CVE
Jul 31, 2025
358 days ago
CVE Severity & Scoring
Jspwiki24 CVEs
79%
17%
All CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network24 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low24 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None3 (12.5%)
Unknown0 (0.0%)
Required21 (87.5%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None24 (100.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (24 CVEs).
24 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-28730MEDIUM A carefully crafted request on AJAXPreview.jsp could trigger an XSS vulnerability on Apache JSPWiki, which could allow the attacker to execute javascript in the victim's browser an | Aug 4, 2022 | 6.1 | 66 | NO | NO |
CVE-2022-27166MEDIUM A carefully crafted request on XHRHtml2Markup.jsp could trigger an XSS vulnerability on Apache JSPWiki up to and including 2.11.2, which could allow the attacker to execute javascr | Aug 4, 2022 | 6.1 | 66 | NO | NO |
CVE-2022-28732MEDIUM A carefully crafted request on WeblogPlugin could trigger an XSS vulnerability on Apache JSPWiki, which could allow the attacker to execute javascript in the victim's browser and g | Aug 4, 2022 | 6.1 | 65 | NO | NO |
CVE-2022-28731MEDIUM A carefully crafted request on UserPreferences.jsp could trigger an CSRF vulnerability on Apache JSPWiki before 2.11.3, which could allow the attacker to modify the email associate | Aug 4, 2022 | 6.5 | 51 | NO | NO |
CVE-2024-27136MEDIUM XSS in Upload page in Apache JSPWiki 2.12.1 and priors allows the attacker to execute javascript in the victim's browser and get some sensitive information about the victim. Apach | Jun 24, 2024 | 6.1 | 45 | NO | NO |
CVE-2021-44140CRITICAL Remote attackers may delete arbitrary files in a system hosting a JSPWiki instance, versions up to 2.11.0.M8, by using a carefuly crafted http request on logout, given that those f | Nov 24, 2021 | 9.1 | 31 | NO | NO |
CVE-2022-24947HIGH Apache JSPWiki user preferences form is vulnerable to CSRF attacks, which can lead to account takeover. Apache JSPWiki users should upgrade to 2.11.2 or later. | Feb 25, 2022 | 8.8 | 28 | NO | NO |
CVE-2019-0225HIGH A specially crafted url could be used to access files under the ROOT directory of the application on Apache JSPWiki 2.9.0 to 2.11.0.M2, which could be used by an attacker to obtain | Mar 28, 2019 | 7.5 | 28 | NO | NO |
CVE-2022-34158HIGH A carefully crafted invocation on the Image plugin could trigger an CSRF vulnerability on Apache JSPWiki before 2.11.3, which could allow a group privilege escalation of the attack | Aug 4, 2022 | 8.8 | 27 | NO | NO |
CVE-2025-24853HIGH A carefully crafted request when creating a header link using the
wiki markup syntax, which could allow the attacker to execute javascript
in the victim's browser and get some se | Jul 31, 2025 | 7.5 | 26 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (24 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (24 CVEs).
Media Mentions
Signals from CVEs in this product scope (24 CVEs).
Top CNAs Publishing CVEs For Jspwiki
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.11.0 | 10 | 6.2 | 3.9% | 0 | 0 |