PatchSiren cyber security CVE debrief
CVE-2026-107800 banq CVE debrief
CVE-2026-107800 is a stored cross-site scripting vulnerability in Jivejdon through version 5.0, allowing authenticated attackers to inject script into private short messages. The vulnerability exists because the receiveshortmessage.jsp page renders unfiltered message bodies. Attackers can send a short message containing script, which ToolsUtil.convertURL() passes through unchanged, to execute code in the recipient's browser when opened.
- Vendor
- banq
- Product
- jivejdon
- CVSS
- MEDIUM 5.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-08
- Original CVE updated
- 2026-10-09
- Advisory published
- 2026-10-08
- Advisory updated
- 2026-10-09
Who should care
Defenders responsible for Jivejdon deployments, particularly those using versions up to 5.0, should assess exposure and verify the effectiveness of current security controls. This includes reviewing system configurations, ensuring proper input validation and output encoding are in place, and implementing additional security measures such as Content Security Policy (CSP) to mitigate XSS attacks. Security teams should also prioritize verifying exposure and
Why it matters
CVE-2026-107800 is a stored cross-site scripting vulnerability in Jivejdon through version 5.0, allowing authenticated attackers to inject script into private short messages. Defenders should prioritize verifying exposure and assessing the effectiveness of current security controls.
- Potential code execution in the recipient's browser when a crafted short message is opened.
- Ability of authenticated attackers to inject script into private short messages.
- Possible impact on the confidentiality and integrity of private short messages.
Technical summary
The vulnerability exists in Jivejdon through version 5.0, where the receiveshortmessage.jsp page renders unfiltered message bodies, allowing attackers to inject script and execute code in the recipient's browser. This occurs because ToolsUtil.convertURL() passes through message content unchanged. The issue enables authenticated attackers to send short messages containing script, which can be executed when opened by the recipient. Defenders should assess the impact of this vulnerability on their deployments and verify the effectiveness of current security controls.
Defensive priority
Defenders should prioritize verifying exposure of Jivejdon versions up to 5.0 and assess the effectiveness of current input validation and output encoding controls.
Recommended defensive actions
- Verify Jivejdon versions up to 5.0 are not in use or are properly patched.
- Assess the effectiveness of current input validation and output encoding controls for private short messages.
- Implement additional security measures, such as Content Security Policy (CSP), to mitigate XSS attacks.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
Evidence notes
The CVE Program record and NVD vulnerability detail provide official information about the vulnerability. Supplemental sources include GitHub issue tracking, product pages, and technical descriptions.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-107800 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-107800
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-107800 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107800
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Jivejdon through 5.0 Stored XSS via Private Short Messages
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107800.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://github.com/banq/jivejdon/issues/28
Supplemental source - issue-tracking
-
Source reference
Unverified legacy reference
URL: https://github.com/banq/jivejdon
Supplemental source - product
-
Source reference
Unverified legacy reference
URL: https://github.com/banq/jivejdon/blob/ee67a65e65228644a71c8317d7e34deea50f95ef/src/main/java/com/jdon/jivejdon/presentation/form/ShortMessageForm.java
Supplemental source - technical-description
-
Source reference
Unverified legacy reference
URL: https://github.com/banq/jivejdon/blob/ee67a65e65228644a71c8317d7e34deea50f95ef/application/shortmessage/receiveshortmessage.jsp
Supplemental source - technical-description
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/jivejdon-through-5.0-stored-xss-via-private-short-messages
Supplemental source - third-party-advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.