CVE-2026-107800: Jivejdon through 5.0 Stored XSS via Private Short Messages
Published Oct 8, 2026
·Updated
Jivejdon through 5.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject script into private short messages because receiveshortmessage.jsp renders unfiltered message bodies. Attackers can send a short message containing script, which ToolsUtil.convertURL() passes through unchanged, to execute code in the recipient's browser when opened.
Affected Software
1 affected component
Jivejdon Jivejdon<=5.0
Event History
Oct 8, 2026
CVE Published
via MITRE·09:51 PM
Data Sourced
via MITRE·09:51 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who is exposed to script execution?
Recipients of private short messages are exposed when they open a malicious message sent by an authenticated attacker.
2
What does an attacker need to exploit this issue?
The attacker needs an authenticated account capable of sending private short messages. They must send a message containing script content and rely on the recipient opening it.
3
Which versions are identified as affected?
Jivejdon versions through 5.0 are identified as affected.