CYBER CODE RED

Get real-time updates on Telegram

P4Verified

CVE-2026-107797: jivejdon 0 through 5.0

CVE-2026-107797. CVSS 3.1 base score 6.1 (GitHub Advisory Database).

Affected technology

jivejdon · 0 through 5.0
banq

Description’s affected range: through 5.0

Component: Not specified by the source

Attack conditions (Vendor/CNA, CVSS 4.0): Network (remote) · No privileges required · Passive user interaction

What an attacker can do

Attackers can send crafted links to authenticated users, breaking out of unencoded inline JavaScript string literals to execute arbitrary JavaScript in the victim's session. Vendor/CNA’s CVSS 4.0 assessment (base score 5.3/10) rates confidentiality and integrity impact as low; availability impact as none.

Published

CWE
CWE-79
CCR priority
24.4 /100 (P4)
CVSS 3.1
6.1 /10 · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N · GitHub Advisory Database
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-107797.html