PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-107800 banq CVE debrief

CVE-2026-107800 is a stored cross-site scripting vulnerability in Jivejdon through version 5.0, allowing authenticated attackers to inject script into private short messages. The vulnerability exists because the receiveshortmessage.jsp page renders unfiltered message bodies. Attackers can send a short message containing script, which ToolsUtil.convertURL() passes through unchanged, to execute code in the recipient's browser when opened.

Vendor
banq
Product
jivejdon
CVSS
MEDIUM 5.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-08
Original CVE updated
2026-10-09
Advisory published
2026-10-08
Advisory updated
2026-10-09

Who should care

Defenders responsible for Jivejdon deployments, particularly those using versions up to 5.0, should assess exposure and verify the effectiveness of current security controls. This includes reviewing system configurations, ensuring proper input validation and output encoding are in place, and implementing additional security measures such as Content Security Policy (CSP) to mitigate XSS attacks. Security teams should also prioritize verifying exposure and

Why it matters

CVE-2026-107800 is a stored cross-site scripting vulnerability in Jivejdon through version 5.0, allowing authenticated attackers to inject script into private short messages. Defenders should prioritize verifying exposure and assessing the effectiveness of current security controls.

  • Potential code execution in the recipient's browser when a crafted short message is opened.
  • Ability of authenticated attackers to inject script into private short messages.
  • Possible impact on the confidentiality and integrity of private short messages.

Technical summary

The vulnerability exists in Jivejdon through version 5.0, where the receiveshortmessage.jsp page renders unfiltered message bodies, allowing attackers to inject script and execute code in the recipient's browser. This occurs because ToolsUtil.convertURL() passes through message content unchanged. The issue enables authenticated attackers to send short messages containing script, which can be executed when opened by the recipient. Defenders should assess the impact of this vulnerability on their deployments and verify the effectiveness of current security controls.

Defensive priority

Defenders should prioritize verifying exposure of Jivejdon versions up to 5.0 and assess the effectiveness of current input validation and output encoding controls.

Recommended defensive actions

  • Verify Jivejdon versions up to 5.0 are not in use or are properly patched.
  • Assess the effectiveness of current input validation and output encoding controls for private short messages.
  • Implement additional security measures, such as Content Security Policy (CSP), to mitigate XSS attacks.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.

Evidence notes

The CVE Program record and NVD vulnerability detail provide official information about the vulnerability. Supplemental sources include GitHub issue tracking, product pages, and technical descriptions.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-107800 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-107800

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-107800 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107800

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Jivejdon through 5.0 Stored XSS via Private Short Messages

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107800.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://github.com/banq/jivejdon/issues/28

    Supplemental source - issue-tracking

  • Source reference

    Unverified legacy reference

    URL: https://github.com/banq/jivejdon

    Supplemental source - product

  • Source reference

    Unverified legacy reference

    URL: https://github.com/banq/jivejdon/blob/ee67a65e65228644a71c8317d7e34deea50f95ef/src/main/java/com/jdon/jivejdon/presentation/form/ShortMessageForm.java

    Supplemental source - technical-description

  • Source reference

    Unverified legacy reference

    URL: https://github.com/banq/jivejdon/blob/ee67a65e65228644a71c8317d7e34deea50f95ef/application/shortmessage/receiveshortmessage.jsp

    Supplemental source - technical-description

  • Source reference

    Unverified legacy reference

    URL: https://www.vulncheck.com/advisories/jivejdon-through-5.0-stored-xss-via-private-short-messages

    Supplemental source - third-party-advisory

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.