CVE-2026-107796: Banq Jivejdon
Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.
Jivejdon from commit 5489372d through commit ee67a65e contains a reflected cross-site scripting vulnerability in application/query/taggedThreadList.jsp that allows unauthenticated attackers to inject script via unencoded tagID and count parameters. Attackers can craft a link with a script-closing payload in tagID or count, triggered when start exceeds zero, to execute JavaScript in victims' browsers.
Affected products
- Banq Jivejdon
Published 2026-10-08. Last modified 2026-10-09.