Unrated severityNVD Advisory· Published Mar 26, 2026· Updated Mar 26, 2026
SAK-52311: Sakai site-manage group titles can contain XSS content
CVE-2026-33402
Description
Sakai is a Collaboration and Learning Environment (CLE). In versions 23.0 through 23.4 and 25.0 through 25.1, group titles and description can contain cross-site scripting scripts. The patch is included in releases 25.2 and 23.5. As a workaround, one can check the SAKAI_SITE_GROUP table for titles and descriptions that contain this info.
Affected products
2- sakaiproject/sakaiv5Range: >= 23.0, < 23.5
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- github.com/sakaiproject/sakai/security/advisories/GHSA-6g62-3898-hpvmmitrex_refsource_CONFIRM
- sakaiproject.atlassian.net/browse/SAK-52311mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.