Vulnerability index

Browse CVEs

14 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Gibbon HIGH 8.8
CVE-2025-26211

Gibbon before 29.0.00 allows CSRF.

Fix: 29.0.00+
Fix from $1,950 2025-05-27
Gibbon MEDIUM 6.1
CVE-2024-34831

cross-site scripting (XSS) vulnerability in Gibbon Core v26.0.00 allows an attacker to execute arbitrary code via the imageLink parameter in the libr…

No fix yet
Fix from $1,600 2024-09-10
Gibbon CRITICAL 9.8
CVE-2024-24724EPSS 26%

Gibbon through 26.0.00 allows /modules/School%20Admin/messengerSettings.php Server Side Template Injection leading to Remote Code Execution because i…

Fix: after 26.0.00
Fix from $2,300 2024-04-03
Gibbon HIGH 8.8
CVE-2024-24725EPSS 51%

Gibbon through 26.0.00 allows remote authenticated users to conduct PHP deserialization attacks via columnOrder in a POST request to the modules/Syst…

Fix: after 26.0.00
Fix from $1,950 2024-03-23
Gibbon CRITICAL 9.8
CVE-2023-45878EPSS 63%

GibbonEdu Gibbon version 25.0.1 and before allows Arbitrary File Write because rubrics_visualise_saveAjax.phps does not require authentication. The e…

Fix: after 25.0.01
Fix from $2,300 2023-11-14
Gibbon HIGH 7.2
CVE-2023-45880

GibbonEdu Gibbon through version 25.0.0 allows Directory Traversal via the report template builder. An attacker can create a new Asset Component. The…

Fix: after 25.0.00
Fix from $1,950 2023-11-14
Gibbon MEDIUM 6.1
CVE-2023-45881

GibbonEdu Gibbon through version 25.0.0 allows /modules/Planner/resources_addQuick_ajaxProcess.php file upload with resultant XSS. The imageAsLinks p…

Fix: after 25.0.00
Fix from $1,600 2023-11-14
Gibbon MEDIUM 5.4
CVE-2023-45879

GibbonEdu Gibbon version 25.0.0 allows HTML Injection via an IFRAME element to the Messager component.

Fix: after 25.0.00
Fix from $1,600 2023-11-14
Gibbon CRITICAL 9.8
CVE-2023-34598EPSS 47%

Gibbon v25.0.0 is vulnerable to a Local File Inclusion (LFI) where it's possible to include the content of several files present in the installation …

No fix yet
Fix from $2,300 2023-06-29
Gibbon MEDIUM 6.1
CVE-2023-34599

Multiple Cross-Site Scripting (XSS) vulnerabilities have been identified in Gibbon v25.0.0, which enable attackers to execute arbitrary Javascript co…

No fix yet
Fix from $1,600 2023-06-29
Gibbon HIGH 8.8
CVE-2022-27305

Gibbon v23 does not generate a new session ID cookie after a user authenticates, making the application vulnerable to session fixation.

Fix: 23.0.02+
Fix from $1,950 2022-05-25
Gibbon MEDIUM 5.4
CVE-2022-23871

Multiple cross-site scripting (XSS) vulnerabilities in the component outcomes_addProcess.php of Gibbon CMS v22.0.01 allow attackers to execute arbitr…

No fix yet
Fix from $1,600 2022-02-03
Gibbon MEDIUM 5.4
CVE-2021-40214

Gibbon v22.0.00 suffers from a stored XSS vulnerability within the wall messages component.

Mitigation only
Fix from $1,600 2021-09-13
Gibbon MEDIUM 6.1
CVE-2021-40492

A reflected XSS vulnerability exists in multiple pages in version 22 of the Gibbon application that allows for arbitrary execution of JavaScript (gib…

Mitigation only
Fix from $1,600 2021-09-03