Unrated severityNVD Advisory· Published Mar 5, 2026· Updated Mar 6, 2026
MarkUs: Stored XSS in Submission HTML Preview Enables Instructor-Context Actions
CVE-2026-28405
Description
MarkUs is a web application for the submission and grading of student assignments. Prior to version 2.9.1, the courses/<:course_id>/assignments/<:assignment_id>/submissions/html_content route reads the contents of a student-submitted file and renders them without sanitization. This issue has been patched in version 2.9.1.
Affected products
2- MarkUsProject/Markusv5Range: < 2.9.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- github.com/MarkUsProject/Markus/commit/55d74f2ddb72d2ec2f29aa2b4cb6b2da10755036mitrex_refsource_MISC
- github.com/MarkUsProject/Markus/releases/tag/v2.9.1mitrex_refsource_MISC
- github.com/MarkUsProject/Markus/security/advisories/GHSA-p5pc-pxrj-3893mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.