CVE-2026-107798: Banq Jivejdon

Medium severity, CVSS 5.4. EPSS: 0.2% chance of exploitation in the next 30 days.

jivejdon from commit 595d8d22 through commit ee67a65e contains a stored cross-site scripting vulnerability in the default-enabled TextStyle filter that inserts unvalidated URLs into anchor href attributes. Authenticated attackers can post messages with javascript: links or quote-breaking URLs to execute JavaScript when other users click or hover over rendered links.

Affected products

Published 2026-10-08. Last modified 2026-10-09.