CVE-2026-107801: Jivejdon through 5.0 Stored XSS via Attachment Upload Content-Type

Published Oct 8, 2026
·
Updated

Jivejdon through 5.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to execute JavaScript by uploading attachments with an attacker-supplied Content-Type. Attackers can upload a file declared as text/html, which UploadShowAction serves inline, and share its link to run JavaScript on the application's origin for viewing users.

Affected Software

1 affected component
Jivejdon Jivejdon<=5.0

Event History

Oct 8, 2026
CVE Published
via MITRE·09:51 PM
Data Sourced
via MITRE·09:51 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue, and who is exposed to the resulting script execution?

An attacker needs an authenticated account with the ability to upload an attachment. Any user who opens a shared link to the uploaded attachment may execute the attacker-controlled JavaScript on the application's origin.

2

What attacker action triggers the vulnerability?

The attacker uploads an attachment while supplying a Content-Type of text/html, then shares the attachment link. UploadShowAction serves that file inline, allowing the browser to interpret it as HTML and run embedded JavaScript.

3

What can be done if an update is not immediately available?

Restrict attachment-upload capability to trusted users and prevent uploaded files from being declared or served as text/html. Avoid opening links to untrusted uploaded attachments until the issue is remediated.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203