CVE-2026-107799
08.10.2026, 22:17
Jivejdon through 5.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject script by posting unsanitized forum message bodies. Message bodies are rendered by messageListBody.jsp with filter="false" and non-escaping default filters, executing script in the browser of every user viewing the thread.
Awaiting analysis
This vulnerability is currently awaiting analysis.
References