---
id: CVE-2026-107797
title: >-
  Jivejdon through 5.0 contains a reflected cross-site scripting vulnerability
  in application/message/postThread.jsp that allows attackers to inject script
  via the to and tag parameters
summary: >-
  Jivejdon through 5.0 contains a reflected cross-site scripting vulnerability
  in application/message/postThread.jsp that allows attackers to inject script
  via the to and tag parameters. Attackers can send crafted links to
  authenticated us…
severity: medium
cvss: 6.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
published: '2026-10-08'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T22:17:29.740'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-107797'
references:
  - url: 'https://github.com/banq/jivejdon'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/banq/jivejdon/blob/ee67a65e65228644a71c8317d7e34deea50f95ef/application/message/postThread.jsp#L54-L72
    label: disclosure@vulncheck.com
  - url: 'https://github.com/banq/jivejdon/issues/28'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/jivejdon-through-5.0-reflected-xss-via-postthread-jsp-to-and-tag-parameters
    label: disclosure@vulncheck.com
tags:
  - nvd
ingestedAt: '2026-10-08T23:16:47.391Z'
---

## Overview

Jivejdon through 5.0 contains a reflected cross-site scripting vulnerability in application/message/postThread.jsp that allows attackers to inject script via the to and tag parameters. Attackers can send crafted links to authenticated users, breaking out of unencoded inline JavaScript string literals to execute arbitrary JavaScript in the victim's session.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
