Apache · Apache Jspwiki · CVE-2026-28813
**Name of the Vulnerable Software and Affected Versions**
Apache JSPWiki versions prior to 2.12.4
**Description**
The software is susceptible to JSON Hijacking, a technique where an attacker steals sensitive data from a JSON response. This flaw subsequently leads to Cross-Site Request Forgery (CSRF), which allows an attacker to trick a victim into performing actions they did not intend to do on the web application.
**Recommendations**
Update to version 2.12.4.