Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:maven/org.apache.jspwiki/jspwiki

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

Apache JSPWiki versions up to 2.12.3 contain a cross-site scripting (XSS) vulnerability due to improper neutralization of script-related HTML tags when parsing markdown rendering errors. This flaw allows an attacker to execute JavaScript in the victim's browser, potentially exposing sensitive information. The issue is fixed in version 2.12.4.

Join the discussion

CVE-2026-28814 is a high-severity vulnerability in Apache JSPWiki up to version 2.12.3 that allows arbitrary Wiki Markup rendering due to lack of authentication. This flaw enables an attacker to access sensitive data stored in JSPWiki variables without requiring any privileges. The issue is resolved in versions 2.12.4 and 3.0.0 by introducing proper authentication controls.

Join the discussion

Apache JSPWiki versions prior to 2.12.4 are vulnerable to a Cross-Site Request Forgery (CSRF) issue related to JSON Hijacking. This vulnerability allows an attacker to perform unauthorized actions on behalf of an authenticated user. The issue is fixed in version 2.12.4.

Join the discussion

UserManager lack of checks allows impersonation in Apache JSPWiki up to 2.12.3 which may allow attackers to escalate privileges. Users are recommended to upgrade to version 2.12.4 or newer which fixes this issue.

Join the discussion

Apache JSPWiki versions prior to 2.12.4 contain a vulnerability where debug messages reveal unnecessary information. This issue is addressed in version 2.12.4. The vulnerability has a high severity score of 7.5 and is identified as CWE-1295.

Join the discussion

Showing 1 to 5 of 5 results

Filters:Package: pkg:maven/org.apache.jspwiki/jspwiki
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses