{"id":"CVE-2019-10089","details":"On Apache JSPWiki, up to version 2.11.0.M4, a carefully crafted plugin link invocation could trigger an XSS vulnerability on Apache JSPWiki, related to the WYSIWYG editor, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim.","aliases":["GHSA-3rx2-x6mx-grj3"],"modified":"2026-09-11T14:11:40.716709Z","published":"2019-09-23T15:15:10.420Z","references":[{"type":"ADVISORY","url":"https://jspwiki-wiki.apache.org/Wiki.jsp?page=CVE-2019-10089"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/apache/jspwiki","events":[{"introduced":"0"},{"last_affected":"1b7f36e1ab997bcdc07f9f27f8ee8f692648411d"},{"introduced":"c2b84e0c9bae48dee127026a4d8a2c68123656dd"},{"last_affected":"c2a7b0b82a551a2ed8994e5f93b9139ab00c167a"}],"database_specific":{"source":["CPE_RANGE","CPE_STRING"],"cpe":["cpe:2.3:a:apache:jspwiki:*:*:*:*:*:*:*:*","cpe:2.3:a:apache:jspwiki:2.11.0:m1:*:*:*:*:*:*","cpe:2.3:a:apache:jspwiki:2.11.0:m1-rc1:*:*:*:*:*:*","cpe:2.3:a:apache:jspwiki:2.11.0:m1-rc2:*:*:*:*:*:*","cpe:2.3:a:apache:jspwiki:2.11.0:m1-rc3:*:*:*:*:*:*","cpe:2.3:a:apache:jspwiki:2.11.0:m2:*:*:*:*:*:*","cpe:2.3:a:apache:jspwiki:2.11.0:m2-rc1:*:*:*:*:*:*","cpe:2.3:a:apache:jspwiki:2.11.0:m3:*:*:*:*:*:*","cpe:2.3:a:apache:jspwiki:2.11.0:m3-rc1:*:*:*:*:*:*","cpe:2.3:a:apache:jspwiki:2.11.0:m3-rc2:*:*:*:*:*:*","cpe:2.3:a:apache:jspwiki:2.11.0:m4:*:*:*:*:*:*","cpe:2.3:a:apache:jspwiki:2.11.0:m4-rc1:*:*:*:*:*:*","cpe:2.3:a:apache:jspwiki:2.11.0:m4-rc2:*:*:*:*:*:*"],"extracted_events":[{"introduced":"0"},{"last_affected":"2.10.5"},{"introduced":"2.11.0-m1"},{"last_affected":"2.11.0-m1"},{"introduced":"2.11.0-m1\\-rc1"},{"last_affected":"2.11.0-m1\\-rc1"},{"introduced":"2.11.0-m1\\-rc2"},{"last_affected":"2.11.0-m1\\-rc2"},{"introduced":"2.11.0-m1\\-rc3"},{"last_affected":"2.11.0-m1\\-rc3"},{"introduced":"2.11.0-m2"},{"last_affected":"2.11.0-m2"},{"introduced":"2.11.0-m2\\-rc1"},{"last_affected":"2.11.0-m2\\-rc1"},{"introduced":"2.11.0-m3"},{"last_affected":"2.11.0-m3"},{"introduced":"2.11.0-m3\\-rc1"},{"last_affected":"2.11.0-m3\\-rc1"},{"introduced":"2.11.0-m3\\-rc2"},{"last_affected":"2.11.0-m3\\-rc2"},{"introduced":"2.11.0-m4"},{"last_affected":"2.11.0-m4"},{"introduced":"2.11.0-m4\\-rc1"},{"last_affected":"2.11.0-m4\\-rc1"},{"introduced":"2.11.0-m4\\-rc2"},{"last_affected":"2.11.0-m4\\-rc2"}]}}],"versions":["2.11.0-m1","2.11.0-m1\\-rc1","2.11.0-m1\\-rc2","2.11.0-m1\\-rc3","2.11.0-m2","2.11.0-m3","2.11.0-m3\\-rc1","2.11.0-m3\\-rc2","2.11.0-m4","2.11.0-m4\\-rc1","2.11.0-m4\\-rc2","2.10.5-RC2","2.10.5","2.10.5-RC1","2.10.4-RC3","2.10.4","2.10.4-RC2","2.10.4-RC1","2.10.3-RC2","2.10.3","2.10.3-RC1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-10089.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}