{
  "affected": [
    {
      "ranges": [
        {
          "database_specific": {
            "extracted_events": [
              {
                "introduced": "0"
              },
              {
                "fixed": "2.12.3"
              }
            ],
            "source": "DESCRIPTION"
          },
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "e04dda38bc9eb06265f368acea3ae04d62834b93"
            }
          ],
          "repo": "https://github.com/apache/jspwiki",
          "type": "GIT"
        }
      ]
    }
  ],
  "database_specific": {
    "cna_assigner": "apache",
    "cwe_ids": [
      "CWE-80"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/48xxx/CVE-2026-48910.json",
    "unresolved_ranges": [
      {
        "extracted_events": [
          {
            "last_affected": "2.12.3"
          }
        ],
        "source": "AFFECTED_FIELD"
      },
      {
        "extracted_events": [
          {
            "fixed": "2.12.3"
          }
        ],
        "source": "DESCRIPTION"
      }
    ]
  },
  "details": "A carefully crafted editing request could trigger an XSS vulnerability \non Apache JSPWiki when parsing errors on the markdown renderer, which \ncould allow the attacker to execute javascript in the victim's browser \nand get some sensitive information about the victim.\n\n\nThis issue affects Apache JSPWiki: through 2.12.3.\n\nUsers are recommended to upgrade to version 2.12.4, which fixes the issue.",
  "id": "CVE-2026-48910",
  "modified": "2026-08-12T03:51:24.182551429Z",
  "published": "2026-07-30T15:56:33.613Z",
  "references": [
    {
      "type": "WEB",
      "url": "http://www.openwall.com/lists/oss-security/2026/07/30/18"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/48xxx/CVE-2026-48910.json"
    },
    {
      "type": "ADVISORY",
      "url": "https://lists.apache.org/thread/yvbdjnocw5qq3xkbjs9h77ghlg0bsw2c"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-48910"
    }
  ],
  "schema_version": "1.9.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
      "type": "CVSS_V3"
    }
  ],
  "summary": "Apache JSPWiki: Markdown parser allows XSS injection in Markdown error processing"
}