{"id":"CVE-2026-107799","summary":"Jivejdon through 5.0 Stored XSS via messageListBody.jsp Forum Message Rendering","details":"Jivejdon through 5.0 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject script by posting unsanitized forum message bodies. Message bodies are rendered by messageListBody.jsp with filter=\"false\" and non-escaping default filters, executing script in the browser of every user viewing the thread.","modified":"2026-10-11T07:05:44.162839532Z","published":"2026-10-08T21:51:30.844Z","database_specific":{"cwe_ids":["CWE-79"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/107xxx/CVE-2026-107799.json","cna_assigner":"VulnCheck"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/107xxx/CVE-2026-107799.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107799"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/jivejdon-through-5.0-stored-xss-via-messagelistbody-jsp-forum-message-rendering"},{"type":"REPORT","url":"https://github.com/banq/jivejdon/issues/28"},{"type":"PACKAGE","url":"https://github.com/banq/jivejdon"},{"type":"ARTICLE","url":"https://github.com/banq/jivejdon/blob/ee67a65e65228644a71c8317d7e34deea50f95ef/application/thread/messageListBody.jsp#L136-L138"},{"type":"ARTICLE","url":"https://github.com/banq/jivejdon/blob/ee67a65e65228644a71c8317d7e34deea50f95ef/src/main/java/com/jdon/jivejdon/domain/model/message/output/RenderingFilterManagerImp.java#L48-L49"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/banq/jivejdon","events":[{"introduced":"0"},{"fixed":"910fafbfa718d0a2be6bb034fa02bcbb580bd731"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"last_affected":"5.0"},{"fixed":"5.0"}],"source":["AFFECTED_FIELD","DESCRIPTION"]}}],"database_specific":{"vanir_signatures_modified":"2026-10-11T07:05:44Z","source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-107799.json","vanir_signatures":[{"target":{"file":"src/com/jdon/jivejdon/manager/mapreduce/ThreadApprovedNewList.java","function":"init"},"deprecated":false,"digest":{"function_hash":"7978373696710798170237061069043931066","length":200},"id":"CVE-2026-107799-10a379ab","signature_type":"Function","signature_version":"v1","source":"https://github.com/banq/jivejdon/commit/910fafbfa718d0a2be6bb034fa02bcbb580bd731"},{"source":"https://github.com/banq/jivejdon/commit/910fafbfa718d0a2be6bb034fa02bcbb580bd731","target":{"file":"src/com/jdon/jivejdon/manager/mapreduce/ThreadApprovedNewList.java"},"deprecated":false,"digest":{"line_hashes":["333860100309000275166928495311066973273","30374915342250970483952060235316732239","81414220211742601704501984076563483847","244416318735342282021764486528743115723","167518763580457859731317481743166481880","271811835294668748424500623578188102863","204948462349554106346462956643280388044","97713261130110039020207586332188831138","309120669949091627681488697821745157699","122748421947153433519081177395231259875","274218177332917631892721971919088235599","41599629172191896058670402327105764117"],"threshold":0.9},"id":"CVE-2026-107799-4ff44e2f","signature_type":"Line","signature_version":"v1"},{"signature_version":"v1","source":"https://github.com/banq/jivejdon/commit/910fafbfa718d0a2be6bb034fa02bcbb580bd731","target":{"function":"isGoodBlog","file":"src/com/jdon/jivejdon/model/query/specification/ApprovedListSpec.java"},"deprecated":false,"digest":{"function_hash":"59108126195409344060918265431689748972","length":137},"id":"CVE-2026-107799-93c70820","signature_type":"Function"},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/banq/jivejdon/commit/910fafbfa718d0a2be6bb034fa02bcbb580bd731","target":{"file":"src/com/jdon/jivejdon/model/query/specification/ApprovedListSpec.java"},"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["185872278007795743557176473001778055140","59525279059624323695607473526051408613","83836500981196697398857103665689467409","121042032624974575198768221417924276931","14004420241609524477760040696659733821","263304077165190376358226209903951123852","49024321835583048676978449252886730798","100467887348313484870724408666892608408"]},"id":"CVE-2026-107799-a326d684"},{"digest":{"function_hash":"147664211641395977390983720950410247303","length":197},"id":"CVE-2026-107799-c28eb86c","signature_type":"Function","signature_version":"v1","source":"https://github.com/banq/jivejdon/commit/910fafbfa718d0a2be6bb034fa02bcbb580bd731","target":{"file":"src/com/jdon/jivejdon/manager/mapreduce/ThreadApprovedNewList.java","function":"start"},"deprecated":false},{"deprecated":false,"digest":{"function_hash":"162596087330417603063677428201438723389","length":122},"id":"CVE-2026-107799-d0745307","signature_type":"Function","signature_version":"v1","source":"https://github.com/banq/jivejdon/commit/910fafbfa718d0a2be6bb034fa02bcbb580bd731","target":{"file":"src/com/jdon/jivejdon/model/query/specification/ApprovedListSpec.java","function":"isExcelledDiscuss"}},{"target":{"file":"src/com/jdon/jivejdon/manager/mapreduce/ThreadApprovedNewList.java","function":"run"},"deprecated":false,"digest":{"function_hash":"208972022311035733844886350694903749572","length":37},"id":"CVE-2026-107799-fd0b7e4d","signature_type":"Function","signature_version":"v1","source":"https://github.com/banq/jivejdon/commit/910fafbfa718d0a2be6bb034fa02bcbb580bd731"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N"}]}