Recent
fast-jwt treats raw public JWK JSON as an HMAC secret, enabling HS256 token forgery
Published 2026-10-08 by GitHub_M
Jivejdon through 5.0 CSRF via GET-based Account and Thread Actions
Published 2026-10-08 by VulnCheck
Jivejdon through commit ee67a65e Missing Rate Limiting via /account/smsVRAction SMS Endpoint
Published 2026-10-08 by VulnCheck
Jivejdon through 5.0 Unsalted MD5 Password Storage via AccountDaoSql
Published 2026-10-08 by VulnCheck
Jivejdon through 5.0 Predictable Passwords via Sina Weibo OAuth Login
Published 2026-10-08 by VulnCheck
Jivejdon through 5.0 Stored XSS via Attachment Upload Content-Type
Published 2026-10-08 by VulnCheck
Jivejdon through 5.0 Stored XSS via Private Short Messages
Published 2026-10-08 by VulnCheck
Jivejdon through 5.0 Stored XSS via messageListBody.jsp Forum Message Rendering
Published 2026-10-08 by VulnCheck
Jivejdon through commit ee67a65e Stored XSS via Markdown Links in TextStyle Rendering Filter
Published 2026-10-08 by VulnCheck
Jivejdon through 5.0 Reflected XSS via postThread.jsp to and tag Parameters
Published 2026-10-08 by VulnCheck
Load more ↓