Jspwiki

Vendor:

First CVE: Feb 11, 2019 · Active for 7 years

24
Total CVEs
More Total CVEs than 95% of tracked products
4.0
Avg CVEs / Year
Higher CVE frequency than 83% of tracked products
6.6
Avg CVSS
Higher Avg CVSS than 32% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Jspwiki over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 11, 2019
7 years ago
Most Recent CVE
Jul 31, 2025
358 days ago

CVE Severity & Scoring

Jspwiki24 CVEs
All CVEs352,231 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network24 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low24 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None3 (12.5%)
Unknown0 (0.0%)
Required21 (87.5%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None24 (100.0%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (24 CVEs).

24 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A carefully crafted request on AJAXPreview.jsp could trigger an XSS vulnerability on Apache JSPWiki, which could allow the attacker to execute javascript in the victim's browser an
Aug 4, 20226.166NONO
A carefully crafted request on XHRHtml2Markup.jsp could trigger an XSS vulnerability on Apache JSPWiki up to and including 2.11.2, which could allow the attacker to execute javascr
Aug 4, 20226.166NONO
A carefully crafted request on WeblogPlugin could trigger an XSS vulnerability on Apache JSPWiki, which could allow the attacker to execute javascript in the victim's browser and g
Aug 4, 20226.165NONO
A carefully crafted request on UserPreferences.jsp could trigger an CSRF vulnerability on Apache JSPWiki before 2.11.3, which could allow the attacker to modify the email associate
Aug 4, 20226.551NONO
XSS in Upload page in Apache JSPWiki 2.12.1 and priors allows the attacker to execute javascript in the victim's browser and get some sensitive information about the victim. Apach
Jun 24, 20246.145NONO
Remote attackers may delete arbitrary files in a system hosting a JSPWiki instance, versions up to 2.11.0.M8, by using a carefuly crafted http request on logout, given that those f
Nov 24, 20219.131NONO
Apache JSPWiki user preferences form is vulnerable to CSRF attacks, which can lead to account takeover. Apache JSPWiki users should upgrade to 2.11.2 or later.
Feb 25, 20228.828NONO
A specially crafted url could be used to access files under the ROOT directory of the application on Apache JSPWiki 2.9.0 to 2.11.0.M2, which could be used by an attacker to obtain
Mar 28, 20197.528NONO
A carefully crafted invocation on the Image plugin could trigger an CSRF vulnerability on Apache JSPWiki before 2.11.3, which could allow a group privilege escalation of the attack
Aug 4, 20228.827NONO
A carefully crafted request when creating a header link using the wiki markup syntax, which could allow the attacker to execute javascript in the victim's browser and get some se
Jul 31, 20257.526NONO

Exploit Exposure

Signals from CVEs in this product scope (24 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (24 CVEs).

Media Mentions

Signals from CVEs in this product scope (24 CVEs).

Top CNAs Publishing CVEs For Jspwiki

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
2.11.0106.23.9%00