VYPR

Conversations

by sakaiproject

CVEs (1)

  • CVE-2026-54049higAug 24, 2026
    risk 0.38cvss epss

    ### Summary The Sakai Conversations tool stores topic and post messages without HTML sanitization, and the frontend renders them using LitElement's `unsafeHTML()` directive, resulting in stored cross-site scripting (XSS). Any authenticated user with access to a site that has…