Vulnerability index

Browse CVEs

72 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Mahara MEDIUM 6.1
CVE-2024-35203

Mahara before 22.10.6, 23.04.6, and 24.04.1 allows cross-site scripting (XSS) via a file, with JavaScript code as part of its name, that is uploaded …

Fix: 22.10.6 / 23.04.6+
Fix from $1,600 2025-08-26
Mahara MEDIUM 5.3
CVE-2024-47192

An issue was discovered in Mahara 23.04.8 and 24.04.4. The use of a malicious export download URL can allow an attacker to download files that they d…

Fix: 23.04.9 / 24.04.5+
Fix from $1,600 2025-08-26
Mahara CRITICAL 9.1
CVE-2024-39335

Supported versions of Mahara 24.04 before 24.04.1 and 23.04 before 23.04.6 are vulnerable to information being disclosed to an institution administra…

Fix: 23.04.6 / 24.04.1+
Fix from $2,300 2025-08-26
Mahara HIGH 7.5
CVE-2025-29992

Mahara before 24.04.9 exposes database connection information if the database becomes unreachable, e.g., due to the database server being temporarily…

Fix: 24.04.9+
Fix from $1,950 2025-08-26
Mahara HIGH 8.8
CVE-2024-47853

An issue was discovered in Mahara 23.04.8 and 24.04.4. Attackers may utilize escalation of privileges in certain cases when logging into Mahara with …

Fix: 23.04.9 / 24.04.5+
Fix from $1,950 2025-08-26
Mahara MEDIUM 6.1
CVE-2024-45753

In Mahara 23.04.8 and 24.04.4, the external RSS feed block can cause XSS if the external feed XML has a malicious value for the link attribute.

Fix: 23.04.9 / 24.04.5+
Fix from $1,600 2025-08-26
Mahara MEDIUM 6.1
CVE-2024-39923

An issue was discovered in Mahara 24.04 before 24.04.2 and 23.04 before 23.04.7. The About, Contact, and Help footer links can be set up to be vulner…

Fix: 23.04.7+
Fix from $1,600 2025-08-25
Mahara HIGH 7.5
CVE-2023-47799

Mahara before 22.10.4 and 23.x before 23.04.4 allows information disclosure if the experimental HTML bulk export is used via the administration inter…

Fix: 22.10.4 / 23.04.4+
Fix from $1,950 2025-08-25
Mahara MEDIUM 6.5
CVE-2022-45133

Mahara 21.10 before 21.10.6, 22.04 before 22.04.4, and 22.10 before 22.10.1 allows unsafe font upload for skins. A particularly structured XML file c…

Fix: 21.10.6 / 22.04.4+
Fix from $1,600 2025-08-22
Mahara CRITICAL 9.8
CVE-2022-45134

Mahara 21.10 before 21.10.6, 22.04 before 22.04.4, and 22.10 before 22.10.1 deserializes user input unsafely during skin import. A particularly struc…

Fix: 21.10.6 / 22.04.4+
Fix from $2,300 2025-08-22
Mahara CRITICAL 9.8
CVE-2022-44544

Mahara 21.04 before 21.04.7, 21.10 before 21.10.5, 22.04 before 22.04.3, and 22.10 before 22.10.0 potentially allow a PDF export to trigger a remote …

Fix: 21.04.7 / 21.10.5+
Fix from $2,300 2022-11-06
Mahara HIGH 7.5
CVE-2022-42707

In Mahara 21.04 before 21.04.7, 21.10 before 21.10.5, 22.04 before 22.04.3, and 22.10 before 22.10.0, embedded images are accessible without a suffic…

Fix: 21.04.7 / 21.10.5+
Fix from $1,950 2022-11-06
Mahara HIGH 7.5
CVE-2022-33913

In Mahara 21.04 before 21.04.6, 21.10 before 21.10.4, and 22.04.2, files can sometimes be downloaded through thumb.php with no permission check.

Fix: 21.04.6 / 21.10.4+
Fix from $1,950 2022-06-20
Mahara HIGH 8.8
CVE-2022-28892

Mahara before 20.10.5, 21.04.4, 21.10.2, and 22.04.0 is vulnerable to Cross Site Request Forgery (CSRF) because randomly generated tokens are too eas…

Fix: 20.10.5 / 21.04.4+
Fix from $1,950 2022-04-28
Mahara HIGH 7.5
CVE-2022-29585

In Mahara before 20.10.5, 21.04.4, 21.10.2, and 22.04.0, a site using Isolated Institutions is vulnerable if more than ten groups are used. They are …

Fix: 20.10.5 / 21.04.4+
Fix from $1,950 2022-04-28
Mahara MEDIUM 5.4
CVE-2022-29584

Mahara before 20.10.5, 21.04.4, 21.10.2, and 22.04.0 allows stored XSS when a particular Cascading Style Sheets (CSS) class for embedly is used, and …

Fix: 20.10.5 / 21.04.4+
Fix from $1,600 2022-04-28
Mahara MEDIUM 5.3
CVE-2022-24111

In Mahara 21.04 before 21.04.3 and 21.10 before 21.10.1, portfolios created in groups that have not been shared with non-group members and portfolios…

Fix: 21.04.3+
Fix from $1,600 2022-02-10
Mahara CRITICAL 9.8
CVE-2021-40849

In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, the account associated with a web services token is vulnerable to being exploited and logged…

Fix: 20.04.5 / 20.10.3+
Fix from $2,300 2021-11-03
Mahara HIGH 7.8
CVE-2021-40848

In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, exported CSV files could contain characters that a spreadsheet program could interpret as a …

Fix: 20.04.5 / 20.10.3+
Fix from $1,950 2021-11-03
Mahara HIGH 7.3
CVE-2021-43266

In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, exporting collections via PDF export could lead to code execution via shell metacharacters i…

Fix: 20.04.5 / 20.10.3+
Fix from $1,950 2021-11-02
Mahara MEDIUM 5.4
CVE-2021-43265

In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, certain tag syntax could be used for XSS, such as via a SCRIPT element.

Fix: 20.04.5 / 20.10.3+
Fix from $1,600 2021-11-02
Mahara MEDIUM 6.5
CVE-2021-29349

Mahara 20.10 is affected by Cross Site Request Forgery (CSRF) that allows a remote attacker to remove inbox-mail on the server. The application fails…

No fix yet
Fix from $1,600 2021-03-31
Mahara MEDIUM 6.1
CVE-2020-15907

In Mahara 19.04 before 19.04.6, 19.10 before 19.10.4, and 20.04 before 20.04.1, certain places could execute file or folder names containing JavaScri…

Fix: 19.04.6 / 19.10.4+
Fix from $1,600 2020-08-07
Mahara MEDIUM 6.5
CVE-2020-9282

In Mahara 18.10 before 18.10.5, 19.04 before 19.04.4, and 19.10 before 19.10.2, certain personal information is discoverable inspecting network respo…

Fix: 18.10.5 / 19.04.4+
Fix from $1,600 2020-03-09
Mahara MEDIUM 6.1
CVE-2013-1426

Cross-site Scripting (XSS) in Mahara before 1.5.9 and 1.6.x before 1.6.4 allows remote attackers to inject arbitrary web script or HTML via the TinyM…

Fix: 1.5.9 / 1.6.4+
Fix from $1,600 2019-11-07
Mahara MEDIUM 5.4
CVE-2019-9709

An issue was discovered in Mahara 17.10 before 17.10.8, 18.04 before 18.04.4, and 18.10 before 18.10.1. The collection title is vulnerable to Cross S…

Fix: 17.10.8 / 18.04.4+
Fix from $1,600 2019-05-07
Mahara HIGH 7.5
CVE-2018-11196

Mahara 17.04 before 17.04.8 and 17.10 before 17.10.5 and 18.04 before 18.04.1 can be used as medium to transmit viruses by placing infected files int…

Fix: 17.04.8 / 17.10.5+
Fix from $1,950 2018-06-01
Mahara MEDIUM 6.8
CVE-2018-11195

Mahara 17.04 before 17.04.8 and 17.10 before 17.10.5 and 18.04 before 18.04.1 are vulnerable to the browser "back and refresh" attack. This allows ma…

Fix: 17.04.8 / 17.10.5+
Fix from $1,600 2018-06-01
Mahara MEDIUM 5.3
CVE-2018-11565

Mahara 17.04 before 17.04.8 and 17.10 before 17.10.5 and 18.04 before 18.04.1 are vulnerable to mentioning the usernames that are already taken by pe…

Fix: 17.04.8 / 17.10.5+
Fix from $1,600 2018-05-30
Mahara MEDIUM 6.1
CVE-2018-6182

Mahara 16.10 before 16.10.9 and 17.04 before 17.04.7 and 17.10 before 17.10.4 are vulnerable to bad input when TinyMCE is bypassed by POST packages. …

Fix: 16.10.9 / 17.04.7+
Fix from $1,600 2018-04-09