These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-107831 is a cross-site request forgery vulnerability in Jivejdon through version 5.0. This vulnerability allows remote attackers to perform state-changing actions via GET endpoints lacking anti-CSRF tokens. The affected product, Jivejdon, is vulnerable to exploitation, which could lead to unauthorized actions on behalf of authenticated users. Defenders should prioritize verifying and mitigating t [truncated]
CVE-2026-107830 is a vulnerability in Jivejdon, a software application developed by banq, that lacks rate limiting on its unauthenticated /account/smsVRAction endpoint. This allows attackers to send unlimited SMS messages, potentially exhausting the operator's Tencent Cloud SMS balance and harassing arbitrary phone numbers. The vulnerability exists in Jivejdon from commit e0306088 through commit ee67a65e. [truncated]
CVE-2026-107829: Jivejdon through 5.0 Unsalted MD5 Password Storage via AccountDaoSql. The CVE record was published on 2026-10-08T21:51:33.503Z and has not been modified since then. This vulnerability is a high-severity issue that stores account passwords as unsalted MD5 digests, allowing for potential password cracking attacks. Defenders should prioritize verification of password storage and authenticati [truncated]
CVE-2026-107828 debrief: Jivejdon 5.0 Predictable Passwords via Sina Weibo OAuth Login. The vulnerability allows unauthenticated attackers to access Weibo-created accounts by deriving predictable credentials from public Weibo user IDs. Defenders should prioritize verifying and remediating vulnerable installations to prevent potential unauthorized access and data breaches. The OAuthAccountServiceImp.transf [truncated]
CVE-2026-107801 is a stored cross-site scripting vulnerability in Jivejdon through version 5.0, which allows authenticated attackers to execute JavaScript by uploading attachments with a specially crafted Content-Type. The vulnerability exists because the application serves uploaded files inline based on their Content-Type, allowing an attacker to upload a file with a Content-Type of text/html and share i [truncated]
CVE-2026-107800 is a stored cross-site scripting vulnerability in Jivejdon through version 5.0, allowing authenticated attackers to inject script into private short messages. The vulnerability exists because the receiveshortmessage.jsp page renders unfiltered message bodies. Attackers can send a short message containing script, which ToolsUtil.convertURL() passes through unchanged, to execute code in the [truncated]
CVE-2026-107799 is a stored cross-site scripting vulnerability in Jivejdon through version 5.0, allowing authenticated attackers to inject script by posting unsanitized forum message bodies. The vulnerability exists because message bodies are rendered by messageListBody.jsp with filter set to false and non-escaping default filters, leading to script execution in the browsers of users viewing the thread.
CVE-2026-107798 is a stored cross-site scripting vulnerability in the TextStyle filter of jivejdon, allowing authenticated attackers to execute JavaScript when other users interact with rendered links. This vulnerability exists from commit 595d8d22 through commit ee67a65e. Defenders should assess exposure and verify the TextStyle filter implementation to prevent JavaScript injection. The vulnerability all [truncated]
CVE-2026-107797 is a reflected cross-site scripting vulnerability in Jivejdon through 5.0, affecting application/message/postThread.jsp. Attackers inject script via to and tag parameters, allowing execution of arbitrary JavaScript in victims' sessions via crafted links. This vulnerability can lead to unauthorized actions or data exposure. Defenders should prioritize verifying exposure, assessing user inte [truncated]
CVE-2026-107796 is a reflected cross-site scripting vulnerability in Jivejdon, a project maintained by banq, from commit 5489372d through commit ee67a65e. The vulnerability is located in the application/query/taggedThreadList.jsp file and allows unauthenticated attackers to inject script via unencoded tagID and count parameters. This vulnerability can be triggered when the start parameter exceeds zero, al [truncated]
CVE-2026-107792 is a missing authorization vulnerability in Jivejdon, allowing authenticated users to move other users' threads by sending crafted requests to /message/threadToForum/save. This issue affects Jivejdon from commit d58a36b0 through ee67a65e. The vulnerability allows for unauthorized thread movement, which could lead to information disclosure or tampering. Defenders should prioritize verifying [truncated]
CVE-2025-71428 Jivejdon SQL Injection Vulnerability. Jivejdon through 5.0 contains a SQL injection vulnerability in AccountDaoSql.getAccountByNameLike() that allows authenticated administrators to inject SQL via the username parameter in the /admin/user/userListAction endpoint. This could lead to unauthorized database access and data exposure. Administrators and developers should assess exposure and prior [truncated]