Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-107800

MEDIUM NVD
CVSS Score 5.4
Severity MEDIUM
Published Oct 08, 2026
Vendor unknown

Description

Jivejdon through 5.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject script into private short messages because receiveshortmessage.jsp renders unfiltered message bodies. Attackers can send a short message containing script, which ToolsUtil.convertURL() passes through unchanged, to execute code in the recipient's browser when opened.

References