GHSA-3x3v-g28r-qvqhMediumCVSS 5.4

Jivejdon through 5.0 contains a stored cross-site scripting vulnerability that allows...

Published
October 9, 2026
Last Modified
October 9, 2026

🔗 CVE IDs covered (1)

📋 Description

Jivejdon through 5.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject script by posting unsanitized forum message bodies. Message bodies are rendered by messageListBody.jsp with filter="false" and non-escaping default filters, executing script in the browser of every user viewing the thread.

🔗 References (7)