JSPWiki is a lightweight, open-source wiki engine with a focused but widely deployed footprint in knowledge-management and collaboration environments. Its vulnerabilities cluster around application-layer input handling—notably cross-site scripting, improper input validation, and path-traversal flaws—and frequently acquire public exploit code, reflecting both the web-facing nature of wiki platforms and the visibility of open-source code to security researchers. Defenders should treat patches for this product as timely and verify that instances exposed to untrusted networks are kept current; live severity and exploitation details are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Jspwiki over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-1230HIGH Unrestricted file upload vulnerability in JSPWiki 2.4.104 and 2.5.139 allows remote attackers to upload and execute arbitrary .jsp files via an unspecified manipulation that attach | Mar 10, 2008 | 9.3 | 37 | NO | YES |
CVE-2008-1231HIGH Directory traversal vulnerability in Edit.jsp in JSPWiki 2.4.104 and 2.5.139 allows remote attackers to include and execute arbitrary local .jsp files, and obtain sensitive informa | Mar 10, 2008 | 9.3 | 36 | NO | YES |
CVE-2008-1229MEDIUM Cross-site scripting (XSS) vulnerability in Edit.jsp in JSPWiki 2.4.104 and 2.5.139 allows remote attackers to inject arbitrary web script or HTML via the editor parameter, a diffe | Mar 10, 2008 | 4.3 | 23 | NO | YES |
CVE-2007-5120MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in JSPWiki 2.4.103 and 2.5.139-beta allow remote attackers to inject arbitrary web script or HTML via the (1) group and (2) memb | Sep 27, 2007 | 4.3 | 21 | NO | YES |
CVE-2007-5119MEDIUM JSPWiki 2.4.103 and 2.5.139-beta allows remote attackers to obtain sensitive information (full path) via an invalid integer in the version parameter to the default URI under attach | Sep 27, 2007 | 4.3 | 14 | NO | NO |
CVE-2007-5121MEDIUM Cross-site scripting (XSS) vulnerability in JSPWiki 2.5.139-beta allows remote attackers to inject arbitrary web script or HTML via the redirect parameter to wiki-3/Login.jsp and u | Sep 27, 2007 | 4.3 | 14 | NO | NO |
CVE-2004-1544MEDIUM Cross-site scripting (XSS) vulnerability in Search.jsp in JSPWiki 2.1.120-cvs and earlier allows remote attackers to execute arbitrary web script as other users via the query param | Dec 31, 2004 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Jspwiki.
Media articles that mention a CVE ID that affects a product developed by Jspwiki — matched by CVE ID, not by vendor name.