Remote attackers may delete arbitrary files in a system hosting a JSPWiki instance, versions up to 2.11.0.M8, by using a carefuly crafted http request on logout, given that those files are reachable to the user running the JSPWiki instance. Apache JSPWiki users should upgrade to 2.11.0 or later.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:HApache Jspwiki
APPApache< 2.11.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
Related vulnerabilities
CVE-2026-28812CRITICAL9.8PL ✓same product
Apache JSPWiki: Podszywanie się pod użytkownika przez brak kontroli w UserManager
CVE-2026-28811HIGH7.5PL ✓same product
Apache JSPWiki: ujawnianie informacji przez komunikaty debugowania
CVE-2026-28814HIGH7.5PL ✓same product
Apache JSPWiki — nieautoryzowane renderowanie Wiki Markup ujawnia dane
CVE-2026-28813HIGH8.8PL ✓same product
Apache JSPWiki – JSON Hijacking prowadzący do podatności CSRF
CVE-2025-24853HIGH7.5same product
A carefully crafted request when creating a header link using the wiki markup syntax, which could allow the a...