VYPR

Banner Self-Service

by Ellucian

CVEs (2)

  • CVE-2026-32856MedJun 9, 2026
    risk 0.40cvss 6.1epss 0.00

    Ellucian Banner Self-Service before the April T2 release (2025-04-23) contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to execute arbitrary JavaScript in a victim's browser by injecting unsanitized input through the toDateFormat…

  • CVE-2026-47106MedJun 9, 2026
    risk 0.35cvss 5.4epss 0.00

    Ellucian Banner Self-Service before the April T2 release (2025-04-23) contains a stored cross-site scripting vulnerability in the course search functionality that allows authenticated Banner ERP users to inject malicious payloads into faculty and course fields by exploiting…