VYPR

Mahara

by Mahara (software)

Source repositories

CVEs (110)

  • CVE-2025-61872MedApr 24, 2026
    risk 0.40cvss 6.1epss 0.00

    Mahara before 25.04.2 and 24.04.11 are vulnerable to displaying results that can trigger XSS via a malicious search query string. This occurs in the 'search site' feature when using the Elasticsearch7 search plugin. The Elasticsearch function does not properly sanitize input in…

  • CVE-2018-6182MedApr 9, 2018
    risk 0.40cvss 6.1epss 0.01

    Mahara 16.10 before 16.10.9 and 17.04 before 17.04.7 and 17.10 before 17.10.4 are vulnerable to bad input when TinyMCE is bypassed by POST packages. Therefore, Mahara should not rely on TinyMCE's code stripping alone but also clean input on the server / PHP side as one can…

  • CVE-2017-9551MedSep 25, 2017
    risk 0.40cvss 6.1epss 0.01

    Mahara 15.04 before 15.04.14 and 16.04 before 16.04.8 and 16.10 before 16.10.5 and 17.04 before 17.04.3 are vulnerable to a user submitting potential dangerous payload, e.g. XSS code, to be saved as their name in the usr_registration table. The values are then emailed to the the…

  • CVE-2017-17455MedFeb 20, 2018
    risk 0.38cvss 5.9epss 0.01

    Mahara 16.10 before 16.10.7, 17.04 before 17.04.5, and 17.10 before 17.10.2 are vulnerable to being forced, via a man-in-the-middle attack, to interact with Mahara on the HTTP protocol rather than HTTPS even when an SSL certificate is present.

  • CVE-2018-11565MedMay 30, 2018
    risk 0.35cvss 5.3epss 0.01

    Mahara 17.04 before 17.04.8 and 17.10 before 17.10.5 and 18.04 before 18.04.1 are vulnerable to mentioning the usernames that are already taken by people registered in the system rather than masking that information.

  • CVE-2017-17454MedFeb 20, 2018
    risk 0.35cvss 5.4epss 0.01

    Mahara 16.10 before 16.10.7 and 17.04 before 17.04.5 and 17.10 before 17.10.2 have a Cross Site Scripting (XSS) vulnerability when a user enters invalid UTF-8 characters. These are now going to be discarded in Mahara along with NULL characters and invalid Unicode characters.…

  • CVE-2017-1000149MedNov 3, 2017
    risk 0.35cvss 5.4epss 0.01

    Mahara 1.10 before 1.10.9 and 15.04 before 15.04.6 and 15.10 before 15.10.2 are vulnerable to XSS due to window.opener (target="_blank" and window.open())

  • CVE-2017-1000146MedNov 3, 2017
    risk 0.35cvss 5.4epss 0.01

    Mahara 1.9 before 1.9.7 and 1.10 before 1.10.5 and 15.04 before 15.04.2 are vulnerable to the arbitrary execution of Javascript in the browser of a logged-in user because the title of the portfolio page was not being properly escaped in the AJAX script that updates the…

  • CVE-2017-1000140MedNov 3, 2017
    risk 0.35cvss 5.4epss 0.01

    Mahara 1.8 before 1.8.7 and 1.9 before 1.9.5 and 1.10 before 1.10.3 and 15.04 before 15.04.0 are vulnerable to a maliciously created .xml file that can have its code executed when user tries to download the file.

  • CVE-2017-1000138MedNov 3, 2017
    risk 0.35cvss 5.4epss 0.01

    Mahara 1.10 before 1.10.0 and 15.04 before 15.04.0 are vulnerable to possible cross site scripting when dragging/dropping files into a collection if the file has Javascript code in its title.

  • CVE-2017-1000137MedNov 3, 2017
    risk 0.35cvss 5.4epss 0.01

    Mahara 1.10 before 1.10.0 and 15.04 before 15.04.0 are vulnerable to possible cross site scripting when adding a text block to a page via the keyboard (rather than drag and drop).

  • CVE-2017-15273MedOct 31, 2017
    risk 0.35cvss 5.4epss 0.01

    Mahara 15.04 before 15.04.15, 16.04 before 16.04.9, 16.10 before 16.10.6, and 17.04 before 17.04.4 are vulnerable to a user submitting a potential dangerous payload, e.g., XSS code, to be saved as titles in internal artefacts.

  • CVE-2017-14752MedOct 31, 2017
    risk 0.35cvss 5.4epss 0.01

    Mahara 15.04 before 15.04.15, 16.04 before 16.04.9, 16.10 before 16.10.6, and 17.04 before 17.04.4 are vulnerable to a user submitting a potential dangerous payload, e.g., XSS code, to be saved as their first name, last name, or display name in the profile fields that can cause…

  • CVE-2017-1000145MedNov 3, 2017
    risk 0.32cvss 4.9epss 0.01

    Mahara 1.9 before 1.9.7 and 1.10 before 1.10.5 and 15.04 before 15.04.2 are vulnerable to anonymous comments being able to be placed on artefact detail pages even when the site administrator had disallowed anonymous comments.

  • CVE-2025-59308MedApr 24, 2026
    risk 0.31cvss 4.7epss 0.00

    In Mahara before 24.04.10 and 25 before 25.04.1, an institution administrator or institution support administrator on a multi-tenanted site can masquerade as an institution member in an institution for which they are not an administrator, if they also have the 'Site staff' role.

  • CVE-2017-1000144MedNov 3, 2017
    risk 0.31cvss 4.8epss 0.01

    Mahara 1.9 before 1.9.6 and 1.10 before 1.10.4 and 15.04 before 15.04.1 are vulnerable to a site admin or institution admin being able to place HTML and Javascript into an institution display name, which will be displayed to other users unescaped on some Mahara system pages.

  • CVE-2017-1000132MedNov 3, 2017
    risk 0.31cvss 4.8epss 0.01

    Mahara 1.8 before 1.8.7 and 1.9 before 1.9.5 and 1.10 before 1.10.3 and 15.04 before 15.04.0 are vulnerable to a maliciously created .swf files that can have its code executed when a user tries to download the file.

  • CVE-2017-1000157MedNov 3, 2017
    risk 0.29cvss 4.4epss 0.01

    Mahara 15.04 before 15.04.13 and 16.04 before 16.04.7 and 16.10 before 16.10.4 and 17.04 before 17.04.2 are vulnerable to recording plain text passwords in the event_log table during the user creation process if full event logging was turned on.

  • CVE-2017-1000155MedNov 3, 2017
    risk 0.28cvss 4.3epss 0.01

    Mahara 15.04 before 15.04.8 and 15.10 before 15.10.4 and 16.04 before 16.04.2 are vulnerable to profile pictures being accessed without any access control checks consequently allowing any of a user's uploaded profile pictures to be viewable by anyone, whether or not they were…

  • CVE-2017-1000143MedNov 3, 2017
    risk 0.28cvss 4.3epss 0.01

    Mahara 1.8 before 1.8.7 and 1.9 before 1.9.5 and 1.10 before 1.10.3 and 15.04 before 15.04.0 are vulnerable to users receiving watchlist notifications about pages they do not have access to anymore.

Page 2 of 6