Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/jivejdon

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

Jivejdon versions up to 5.0 have a cross-site request forgery (CSRF) vulnerability. This flaw allows remote attackers to trick authenticated users into performing unwanted state-changing actions via GET requests that lack anti-CSRF tokens. Exploitable endpoints include those for deleting private messages and subscriptions or renaming threads.

Join the discussion

CVE-2026-107830 is a medium severity vulnerability in the banq jivejdon product. It involves a lack of rate limiting on the unauthenticated /account/smsVRAction endpoint, allowing attackers to send unlimited SMS messages. This can be exploited to harass arbitrary phone numbers and exhaust the operator's Tencent Cloud SMS balance. The vulnerability affects versions of jivejdon from commit e0306088 through commit ee67a65e. No patch or remediation information is provided.

Join the discussion

Jivejdon versions up to 5.0 use unsalted MD5 hashes for password storage, which is cryptographically weak. This allows attackers who gain database access or exploit SQL injection vulnerabilities to efficiently crack user passwords using precomputed tables or GPU-accelerated attacks.

Join the discussion
0

Jivejdon versions up to 5.0 have an authentication bypass vulnerability due to weak credential derivation. The OAuthAccountServiceImp.transferSina() method sets user passwords to the first four digits of their public Weibo user IDs, allowing unauthenticated attackers to log in as those users. This enables attackers to read or post content on behalf of victims without authorization.

Join the discussion

Jivejdon versions up to 5.0 contain a stored cross-site scripting (XSS) vulnerability. Authenticated attackers can exploit this by uploading attachments with a crafted Content-Type header, such as text/html, causing the application to serve the file inline and execute attacker-supplied JavaScript in the context of the application for users who view the link.

Join the discussion

Jivejdon versions up to 5.0 contain a stored cross-site scripting (XSS) vulnerability in the private short message feature. Authenticated attackers can inject malicious scripts into message bodies because the application renders unfiltered content in receiveshortmessage.jsp. This allows execution of attacker-controlled code in the recipient's browser when the message is opened.

Join the discussion

Jivejdon versions up to 5.0 contain a stored cross-site scripting (XSS) vulnerability. Authenticated attackers can inject malicious scripts into forum message bodies, which are rendered without proper sanitization. This causes the injected scripts to execute in the browsers of users viewing the affected threads.

Join the discussion

CVE-2026-107798 is a stored cross-site scripting (XSS) vulnerability in the banq jivejdon product. It affects versions from commit 595d8d22 through commit ee67a65e. The vulnerability arises from the default-enabled TextStyle filter that inserts unvalidated URLs into anchor href attributes, allowing authenticated attackers to post messages containing malicious javascript: links or malformed URLs. When other users interact with these links, JavaScript code can execute in their browsers. The CVSS 4.0 base score is 5.1, indicating a medium severity level.

Join the discussion

Jivejdon versions up to 5.0 contain a reflected cross-site scripting (XSS) vulnerability in the application/message/postThread.jsp component. This flaw allows attackers to inject malicious scripts via the 'to' and 'tag' parameters. Exploitation requires tricking authenticated users into clicking crafted links, which then execute arbitrary JavaScript in their session context.

Join the discussion

Jivejdon contains a reflected cross-site scripting (XSS) vulnerability in the application/query/taggedThreadList.jsp page. This flaw allows unauthenticated attackers to inject malicious scripts via the unencoded tagID and count parameters. The vulnerability is triggered when the start parameter exceeds zero, enabling execution of arbitrary JavaScript in the victim's browser.

Join the discussion

Showing 1 to 10 of 13 results

Filters:Package: pkg:github/jivejdon
Page 1 of 2
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses