CVE-2026-107829EPSS p8.6%
CVE-2026-107829CVE-2026-107829
Description
Jivejdon through 5.0 contains a weak password storage vulnerability that stores account passwords as unsalted MD5 digests via ToolsUtil.hash() in AccountDaoSql. Attackers who obtain the user table through database access or SQL injection can crack passwords with precomputed tables or GPU attacks.
Scoring
| CVSS | 5.9 () |
| Vector | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N |
| EPSS | 0.20% probability of exploitation · percentile 8.6% · 2026-10-10T12:00:23Z |
| Last modified | 2026-10-09 |