Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.1
CVE-2024-35203
Mahara before 22.10.6, 23.04.6, and 24.04.1 allows cross-site scripting (XSS) via a file, with JavaScript code as part of its name, that is uploaded …
Mahara
22.10.6 / 23.04.6+
MEDIUM 5.3
CVE-2024-47192
An issue was discovered in Mahara 23.04.8 and 24.04.4. The use of a malicious export download URL can allow an attacker to download files that they d…
Mahara
23.04.9 / 24.04.5+
CRITICAL 9.1
CVE-2024-39335
Supported versions of Mahara 24.04 before 24.04.1 and 23.04 before 23.04.6 are vulnerable to information being disclosed to an institution administra…
Mahara
23.04.6 / 24.04.1+
HIGH 7.5
CVE-2025-29992
Mahara before 24.04.9 exposes database connection information if the database becomes unreachable, e.g., due to the database server being temporarily…
Mahara
24.04.9+
HIGH 8.8
CVE-2024-47853
An issue was discovered in Mahara 23.04.8 and 24.04.4. Attackers may utilize escalation of privileges in certain cases when logging into Mahara with …
Mahara
23.04.9 / 24.04.5+
MEDIUM 6.1
CVE-2024-45753
In Mahara 23.04.8 and 24.04.4, the external RSS feed block can cause XSS if the external feed XML has a malicious value for the link attribute.
Mahara
23.04.9 / 24.04.5+
MEDIUM 6.1
CVE-2024-39923
An issue was discovered in Mahara 24.04 before 24.04.2 and 23.04 before 23.04.7. The About, Contact, and Help footer links can be set up to be vulner…
Mahara
23.04.7+
HIGH 7.5
CVE-2023-47799
Mahara before 22.10.4 and 23.x before 23.04.4 allows information disclosure if the experimental HTML bulk export is used via the administration inter…
Mahara
22.10.4 / 23.04.4+
MEDIUM 6.5
CVE-2022-45133
Mahara 21.10 before 21.10.6, 22.04 before 22.04.4, and 22.10 before 22.10.1 allows unsafe font upload for skins. A particularly structured XML file c…
Mahara
21.10.6 / 22.04.4+
CRITICAL 9.8
CVE-2022-45134
Mahara 21.10 before 21.10.6, 22.04 before 22.04.4, and 22.10 before 22.10.1 deserializes user input unsafely during skin import. A particularly struc…
Mahara
21.10.6 / 22.04.4+
CRITICAL 9.8
CVE-2022-44544
Mahara 21.04 before 21.04.7, 21.10 before 21.10.5, 22.04 before 22.04.3, and 22.10 before 22.10.0 potentially allow a PDF export to trigger a remote …
Mahara
21.04.7 / 21.10.5+
HIGH 7.5
CVE-2022-42707
In Mahara 21.04 before 21.04.7, 21.10 before 21.10.5, 22.04 before 22.04.3, and 22.10 before 22.10.0, embedded images are accessible without a suffic…
Mahara
21.04.7 / 21.10.5+
HIGH 7.5
CVE-2022-33913
In Mahara 21.04 before 21.04.6, 21.10 before 21.10.4, and 22.04.2, files can sometimes be downloaded through thumb.php with no permission check.
Mahara
21.04.6 / 21.10.4+
HIGH 8.8
CVE-2022-28892
Mahara before 20.10.5, 21.04.4, 21.10.2, and 22.04.0 is vulnerable to Cross Site Request Forgery (CSRF) because randomly generated tokens are too eas…
Mahara
20.10.5 / 21.04.4+
HIGH 7.5
CVE-2022-29585
In Mahara before 20.10.5, 21.04.4, 21.10.2, and 22.04.0, a site using Isolated Institutions is vulnerable if more than ten groups are used. They are …
Mahara
20.10.5 / 21.04.4+
MEDIUM 5.4
CVE-2022-29584
Mahara before 20.10.5, 21.04.4, 21.10.2, and 22.04.0 allows stored XSS when a particular Cascading Style Sheets (CSS) class for embedly is used, and …
Mahara
20.10.5 / 21.04.4+
MEDIUM 5.3
CVE-2022-24111
In Mahara 21.04 before 21.04.3 and 21.10 before 21.10.1, portfolios created in groups that have not been shared with non-group members and portfolios…
Mahara
21.04.3+
CRITICAL 9.8
CVE-2021-40849
In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, the account associated with a web services token is vulnerable to being exploited and logged…
Mahara
20.04.5 / 20.10.3+
HIGH 7.8
CVE-2021-40848
In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, exported CSV files could contain characters that a spreadsheet program could interpret as a …
Mahara
20.04.5 / 20.10.3+
HIGH 7.3
CVE-2021-43266
In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, exporting collections via PDF export could lead to code execution via shell metacharacters i…
Mahara
20.04.5 / 20.10.3+
MEDIUM 5.4
CVE-2021-43265
In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, certain tag syntax could be used for XSS, such as via a SCRIPT element.
Mahara
20.04.5 / 20.10.3+
MEDIUM 6.5
CVE-2021-29349
Mahara 20.10 is affected by Cross Site Request Forgery (CSRF) that allows a remote attacker to remove inbox-mail on the server. The application fails…
Mahara
No fix yet
MEDIUM 6.1
CVE-2020-15907
In Mahara 19.04 before 19.04.6, 19.10 before 19.10.4, and 20.04 before 20.04.1, certain places could execute file or folder names containing JavaScri…
Mahara
19.04.6 / 19.10.4+
MEDIUM 6.5
CVE-2020-9282
In Mahara 18.10 before 18.10.5, 19.04 before 19.04.4, and 19.10 before 19.10.2, certain personal information is discoverable inspecting network respo…
Mahara
18.10.5 / 19.04.4+
MEDIUM 6.1
CVE-2013-1426
Cross-site Scripting (XSS) in Mahara before 1.5.9 and 1.6.x before 1.6.4 allows remote attackers to inject arbitrary web script or HTML via the TinyM…
Mahara
1.5.9 / 1.6.4+
MEDIUM 5.4
CVE-2019-9709
An issue was discovered in Mahara 17.10 before 17.10.8, 18.04 before 18.04.4, and 18.10 before 18.10.1. The collection title is vulnerable to Cross S…
Mahara
17.10.8 / 18.04.4+
HIGH 7.5
CVE-2018-11196
Mahara 17.04 before 17.04.8 and 17.10 before 17.10.5 and 18.04 before 18.04.1 can be used as medium to transmit viruses by placing infected files int…
Mahara
17.04.8 / 17.10.5+
MEDIUM 6.8
CVE-2018-11195
Mahara 17.04 before 17.04.8 and 17.10 before 17.10.5 and 18.04 before 18.04.1 are vulnerable to the browser "back and refresh" attack. This allows ma…
Mahara
17.04.8 / 17.10.5+
MEDIUM 5.3
CVE-2018-11565
Mahara 17.04 before 17.04.8 and 17.10 before 17.10.5 and 18.04 before 18.04.1 are vulnerable to mentioning the usernames that are already taken by pe…
Mahara
17.04.8 / 17.10.5+
MEDIUM 6.1
CVE-2018-6182
Mahara 16.10 before 16.10.9 and 17.04 before 17.04.7 and 17.10 before 17.10.4 are vulnerable to bad input when TinyMCE is bypassed by POST packages. …
Mahara
16.10.9 / 17.04.7+