Cross-site Request Forgery (CSRF) Affecting org.apache.jspwiki:jspwiki-main package, versions [,2.12.4-RC2)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.19% (9th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-ORGAPACHEJSPWIKI-19500658
  • published2 Sept 2026
  • disclosed30 Jul 2026
  • creditJanne Jalkannen

Introduced: 30 Jul 2026

CVE-2026-28813  (opens in a new tab)
CWE-352  (opens in a new tab)

How to fix?

Upgrade org.apache.jspwiki:jspwiki-main to version 2.12.4-RC2 or higher.

Overview

org.apache.jspwiki:jspwiki-main is a main release jar for Apache JSPWiki engine.

Affected versions of this package are vulnerable to Cross-site Request Forgery (CSRF) through the AJAXPreview.jsp preview handler in jspwiki-war/src/main/webapp/templates/default/AJAXPreview.jsp and its caller in jspwiki-war/src/main/scripts/jspwiki-edit.js. An attacker can force a victim’s browser to issue a cross-site preview request by sending a crafted GET request to the AJAX preview endpoint, causing the application to process editable wiki markup without CSRF protection. This can expose or manipulate previewed page content in the user’s session and let an attacker drive unwanted edit-related actions from the victim’s browser. As a result, users can be tricked into performing preview requests that the application treats as part of an edit workflow.

CVSS Base Scores

version 4.0
version 3.1