CVE-2026-28813: Apache JSPWiki: JSPWiki vulnerable to JSON hijacking
Published Jul 30, 2026
·Updated
Apache JSPWiki, up to 2.12.3, is vulnerable to JSON Hijacking, which leads to csrf vulnerabilities. Users are recommended to upgrade to version 2.12.4, which fixes this issue.
Affected Software
2 affected components
Apache JSPWiki<=2.12.3
Apache JSPWiki<2.12.4
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache JSPWikito a version that resolves this vulnerability.Fixed in 2.12.4
Event History
Jul 30, 2026
CVE Published
via MITRE·03:54 PM
Data Sourced
via MITRE·03:54 PM
DescriptionWeakness
Data Sourced
via NVD·04:17 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-28813?
CVE-2026-28813 has a risk score of 26, indicating a significant security vulnerability.
2
What are the implications of the vulnerability CVE-2026-28813?
CVE-2026-28813 is vulnerable to JSON hijacking, which can lead to CSRF attacks.
3
How do I fix CVE-2026-28813?
To fix CVE-2026-28813, users should upgrade Apache JSPWiki to version 2.12.4 or later.
4
Which versions of Apache JSPWiki are affected by CVE-2026-28813?
Apache JSPWiki versions up to 2.12.3 are affected by CVE-2026-28813.
5
What types of attacks are possible due to CVE-2026-28813?
CVE-2026-28813 can lead to CSRF vulnerabilities due to JSON hijacking.