VYPR
Unrated severityNVD Advisory· Published Mar 26, 2026· Updated Mar 26, 2026

SAK-52311: Sakai site-manage group titles can contain XSS content

CVE-2026-33402

Description

Sakai is a Collaboration and Learning Environment (CLE). In versions 23.0 through 23.4 and 25.0 through 25.1, group titles and description can contain cross-site scripting scripts. The patch is included in releases 25.2 and 23.5. As a workaround, one can check the SAKAI_SITE_GROUP table for titles and descriptions that contain this info.

Affected products

2
  • Sakai/Sakai CLEllm-create
    Range: 23.0-23.4, 25.0-25.1
  • sakaiproject/sakaiv5
    Range: >= 23.0, < 23.5

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.