VYPR

Vendor CVEs

Mahara (software)

All CVEs

111 total · sorted by risk
  • CVE-2022-45134CriAug 22, 2025
    risk 0.64cvss 9.8epss 0.01

    Mahara 21.10 before 21.10.6, 22.04 before 22.04.4, and 22.10 before 22.10.1 deserializes user input unsafely during skin import. A particularly structured XML file could cause code execution when being processed.

  • CVE-2022-44544CriNov 6, 2022
    risk 0.64cvss 9.8epss 0.01

    Mahara 21.04 before 21.04.7, 21.10 before 21.10.5, 22.04 before 22.04.3, and 22.10 before 22.10.0 potentially allow a PDF export to trigger a remote shell if the site is running on Ubuntu and the flag -dSAFER is not set with Ghostscript.

  • CVE-2021-40849CriNov 3, 2021
    risk 0.64cvss 9.8epss 0.01

    In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, the account associated with a web services token is vulnerable to being exploited and logged into, resulting in information disclosure (at a minimum) and often escalation of privileges.

  • CVE-2017-1000171CriNov 3, 2017
    risk 0.64cvss 9.8epss 0.01

    Mahara Mobile before 1.2.1 is vulnerable to passwords being sent to the Mahara access log in plain text.

  • CVE-2017-1000154CriNov 3, 2017
    risk 0.64cvss 9.8epss 0.01

    Mahara 15.04 before 15.04.8 and 15.10 before 15.10.4 and 16.04 before 16.04.2 are vulnerable to some authentication methods, which do not use Mahara's built-in login form, still allowing users to log in even if their institution was expired or suspended.

  • CVE-2017-1000153CriNov 3, 2017
    risk 0.64cvss 9.8epss 0.01

    Mahara 15.04 before 15.04.10 and 15.10 before 15.10.6 and 16.04 before 16.04.4 are vulnerable to incorrect access control after the password reset link is sent via email and then user changes default email, Mahara fails to invalidate old link.Consequently the link in email can…

  • CVE-2017-1000152CriNov 3, 2017
    risk 0.64cvss 9.8epss 0.01

    Mahara 15.04 before 15.04.7 and 15.10 before 15.10.3 running PHP 5.3 are vulnerable to one user being logged in as another user on a separate computer as the same session ID is served. This situation can occur when a user takes an action that forces another user to be logged out…

  • CVE-2024-39335CriAug 26, 2025
    risk 0.59cvss 9.1epss 0.00

    Supported versions of Mahara 24.04 before 24.04.1 and 23.04 before 23.04.6 are vulnerable to information being disclosed to an institution administrator under certain conditions via the 'Current submissions' page: Administration -> Groups -> Submissions.

  • CVE-2012-2239CriNov 24, 2012
    risk 0.59cvss 9.1epss 0.02

    Mahara 1.4.x before 1.4.4 and 1.5.x before 1.5.3 allows remote attackers to read arbitrary files or create TCP connections via an XML external entity (XXE) injection attack, as demonstrated by reading config.php.

  • CVE-2024-47853HigAug 26, 2025
    risk 0.57cvss 8.8epss 0.00

    An issue was discovered in Mahara 23.04.8 and 24.04.4. Attackers may utilize escalation of privileges in certain cases when logging into Mahara with Learning Tools Interoperability (LTI).

  • CVE-2022-28892HigApr 28, 2022
    risk 0.57cvss 8.8epss 0.00

    Mahara before 20.10.5, 21.04.4, 21.10.2, and 22.04.0 is vulnerable to Cross Site Request Forgery (CSRF) because randomly generated tokens are too easily guessable.

  • CVE-2017-1000150HigNov 3, 2017
    risk 0.57cvss 8.8epss 0.01

    Mahara 15.04 before 15.04.7 and 15.10 before 15.10.3 are vulnerable to prevent session IDs from being regenerated on login or logout. This makes users of the site more vulnerable to session fixation attacks.

  • CVE-2017-1000148HigNov 3, 2017
    risk 0.57cvss 8.8epss 0.02

    Mahara 15.04 before 15.04.8 and 15.10 before 15.10.4 and 16.04 before 16.04.2 are vulnerable to PHP code execution as Mahara would pass portions of the XML through the PHP "unserialize()" function when importing a skin from an XML file.

  • CVE-2017-14163HigOct 31, 2017
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in Mahara before 15.04.14, 16.x before 16.04.8, 16.10.x before 16.10.5, and 17.x before 17.04.3. When one closes the browser without logging out of Mahara, the value in the usr_session table is not removed. If someone were to open a browser, visit the…

  • CVE-2017-1000134HigNov 3, 2017
    risk 0.53cvss 8.1epss 0.01

    Mahara 1.8 before 1.8.6 and 1.9 before 1.9.4 and 1.10 before 1.10.1 and 15.04 before 15.04.0 are vulnerable because group members can lose access to the group files they uploaded if another group member changes the access permissions on them.

  • CVE-2017-1000139HigNov 3, 2017
    risk 0.52cvss 8.0epss 0.01

    Mahara 1.8 before 1.8.7 and 1.9 before 1.9.5 and 1.10 before 1.10.3 and 15.04 before 15.04.0 are vulnerable to server-side request forgery attacks as not all processes of curl redirects are checked against a white or black list. Employing SafeCurl will prevent issues.

  • CVE-2021-40848HigNov 3, 2021
    risk 0.51cvss 7.8epss 0.01

    In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, exported CSV files could contain characters that a spreadsheet program could interpret as a command, leading to execution of a malicious string locally on a device, aka CSV injection.

  • CVE-2025-29992HigAug 26, 2025
    risk 0.49cvss 7.5epss 0.00

    Mahara before 24.04.9 exposes database connection information if the database becomes unreachable, e.g., due to the database server being temporarily down or too busy.

  • CVE-2023-47799HigAug 25, 2025
    risk 0.49cvss 7.5epss 0.00

    Mahara before 22.10.4 and 23.x before 23.04.4 allows information disclosure if the experimental HTML bulk export is used via the administration interface or via the CLI, and the resulting export files are given to the account holders. They may contain images of other account…

  • CVE-2022-42707HigNov 6, 2022
    risk 0.49cvss 7.5epss 0.01

    In Mahara 21.04 before 21.04.7, 21.10 before 21.10.5, 22.04 before 22.04.3, and 22.10 before 22.10.0, embedded images are accessible without a sufficient permission check under certain conditions.

  • CVE-2022-33913HigJun 20, 2022
    risk 0.49cvss 7.5epss 0.01

    In Mahara 21.04 before 21.04.6, 21.10 before 21.10.4, and 22.04.2, files can sometimes be downloaded through thumb.php with no permission check.

  • CVE-2022-29585HigApr 28, 2022
    risk 0.49cvss 7.5epss 0.01

    In Mahara before 20.10.5, 21.04.4, 21.10.2, and 22.04.0, a site using Isolated Institutions is vulnerable if more than ten groups are used. They are all shown from page 2 of the group results list (rather than only being shown for the institution that the viewer is a member of).

  • CVE-2018-11196HigJun 1, 2018
    risk 0.49cvss 7.5epss 0.01

    Mahara 17.04 before 17.04.8 and 17.10 before 17.10.5 and 18.04 before 18.04.1 can be used as medium to transmit viruses by placing infected files into a Leap2A archive and uploading that to Mahara. In contrast to other ZIP files that are uploaded, ClamAV (when activated) does…

  • CVE-2017-1000151HigNov 3, 2017
    risk 0.49cvss 7.5epss 0.01

    Mahara 15.04 before 15.04.9 and 15.10 before 15.10.5 and 16.04 before 16.04.3 are vulnerable to passwords or other sensitive information being passed by unusual parameters to end up in an error log.

  • CVE-2017-1000133HigNov 3, 2017
    risk 0.49cvss 7.5epss 0.01

    Mahara 15.04 before 15.04.8 and 15.10 before 15.10.4 and 16.04 before 16.04.2 are vulnerable to a user - in some circumstances causing another user's artefacts to be included in a Leap2a export of their own pages.

  • CVE-2021-43266HigNov 2, 2021
    risk 0.48cvss 7.3epss 0.01

    In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, exporting collections via PDF export could lead to code execution via shell metacharacters in a collection name. Additional, in Mahara before 20.10.4, 21.04.3, and 21.10.1, exporting collections via PDF export could cause…

  • CVE-2018-11195MedJun 1, 2018
    risk 0.44cvss 6.8epss 0.01

    Mahara 17.04 before 17.04.8 and 17.10 before 17.10.5 and 18.04 before 18.04.1 are vulnerable to the browser "back and refresh" attack. This allows malicious users with physical access to the web browser of a Mahara user, after they have logged in, to potentially gain access to…

  • CVE-2017-1000147MedNov 3, 2017
    risk 0.44cvss 6.8epss 0.00

    Mahara 1.9 before 1.9.8 and 1.10 before 1.10.6 and 15.04 before 15.04.3 are vulnerable to perform a cross-site request forgery (CSRF) attack on the uploader contained in Mahara's filebrowser widget. This could allow an attacker to trick a Mahara user into unknowingly uploading…

  • CVE-2012-2237MedDec 17, 2019
    risk 0.43cvss 6.1epss 0.03

    Multiple cross-site scripting (XSS) vulnerabilities in Mahara 1.4.x before 1.4.3 and 1.5.x before 1.5.2 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) javascript innerHTML as used when generating login forms, (2) links or (3) resources…

  • CVE-2022-45133MedAug 22, 2025
    risk 0.42cvss 6.5epss 0.00

    Mahara 21.10 before 21.10.6, 22.04 before 22.04.4, and 22.10 before 22.10.1 allows unsafe font upload for skins. A particularly structured XML file could allow one to traverse the server to obtain access to secure files or cause code execution based on the payload.

  • CVE-2021-29349MedMar 31, 2021
    risk 0.42cvss 6.5epss 0.02

    Mahara 20.10 is affected by Cross Site Request Forgery (CSRF) that allows a remote attacker to remove inbox-mail on the server. The application fails to validate the CSRF token for a POST request. An attacker can craft a module/multirecipientnotification/inbox.php…

  • CVE-2020-9282MedMar 9, 2020
    risk 0.42cvss 6.5epss 0.01

    In Mahara 18.10 before 18.10.5, 19.04 before 19.04.4, and 19.10 before 19.10.2, certain personal information is discoverable inspecting network responses on the 'Edit access' screen when sharing portfolios.

  • CVE-2017-1000141MedJan 30, 2018
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in Mahara before 18.10.0. It mishandled user requests that could discontinue a user's ability to maintain their own account (changing username, changing primary email address, deleting account). The correct behavior was to either prompt them for their…

  • CVE-2017-1000156MedNov 3, 2017
    risk 0.42cvss 6.5epss 0.01

    Mahara 15.04 before 15.04.9 and 15.10 before 15.10.5 and 16.04 before 16.04.3 are vulnerable to a group's configuration page being editable by any group member even when they didn't have the admin role.

  • CVE-2017-1000142MedNov 3, 2017
    risk 0.42cvss 6.5epss 0.01

    Mahara 1.8 before 1.8.7 and 1.9 before 1.9.5 and 1.10 before 1.10.3 and 15.04 before 15.04.0 are vulnerable to users being able to delete their submitted page through URL manipulation.

  • CVE-2017-1000136MedNov 3, 2017
    risk 0.42cvss 6.5epss 0.01

    Mahara 1.8 before 1.8.6 and 1.9 before 1.9.4 and 1.10 before 1.10.1 and 15.04 before 15.04.0 are vulnerable to old sessions not being invalidated after a password change.

  • CVE-2017-1000135MedNov 3, 2017
    risk 0.42cvss 6.5epss 0.01

    Mahara 1.8 before 1.8.7 and 1.9 before 1.9.5 and 1.10 before 1.10.3 and 15.04 before 15.04.0 are vulnerable as logged-in users can stay logged in after the institution they belong to is suspended.

  • CVE-2017-1000131MedNov 3, 2017
    risk 0.42cvss 6.5epss 0.01

    Mahara 15.04 before 15.04.8 and 15.10 before 15.10.4 and 16.04 before 16.04.2 are vulnerable to users staying logged in to their Mahara account even when they have been logged out of Moodle (when using MNet) as Mahara did not properly implement one of the MNet SSO API functions.

  • CVE-2025-61872MedApr 24, 2026
    risk 0.40cvss 6.1epss 0.00

    Mahara before 25.04.2 and 24.04.11 are vulnerable to displaying results that can trigger XSS via a malicious search query string. This occurs in the 'search site' feature when using the Elasticsearch7 search plugin. The Elasticsearch function does not properly sanitize input in…

  • CVE-2024-35203MedAug 26, 2025
    risk 0.40cvss 6.1epss 0.00

    Mahara before 22.10.6, 23.04.6, and 24.04.1 allows cross-site scripting (XSS) via a file, with JavaScript code as part of its name, that is uploaded via the Mahara filebrowser system.

  • CVE-2024-45753MedAug 26, 2025
    risk 0.40cvss 6.1epss 0.00

    In Mahara 23.04.8 and 24.04.4, the external RSS feed block can cause XSS if the external feed XML has a malicious value for the link attribute.

  • CVE-2024-39923MedAug 25, 2025
    risk 0.40cvss 6.1epss 0.00

    An issue was discovered in Mahara 24.04 before 24.04.2 and 23.04 before 23.04.7. The About, Contact, and Help footer links can be set up to be vulnerable to Cross Site Scripting (XSS) due to not sanitising the values. These links can only be set up by an admin but are clickable…

  • CVE-2020-15907MedAug 7, 2020
    risk 0.40cvss 6.1epss 0.01

    In Mahara 19.04 before 19.04.6, 19.10 before 19.10.4, and 20.04 before 20.04.1, certain places could execute file or folder names containing JavaScript.

  • CVE-2018-6182MedApr 9, 2018
    risk 0.40cvss 6.1epss 0.01

    Mahara 16.10 before 16.10.9 and 17.04 before 17.04.7 and 17.10 before 17.10.4 are vulnerable to bad input when TinyMCE is bypassed by POST packages. Therefore, Mahara should not rely on TinyMCE's code stripping alone but also clean input on the server / PHP side as one can…

  • CVE-2017-9551MedSep 25, 2017
    risk 0.40cvss 6.1epss 0.01

    Mahara 15.04 before 15.04.14 and 16.04 before 16.04.8 and 16.10 before 16.10.5 and 17.04 before 17.04.3 are vulnerable to a user submitting potential dangerous payload, e.g. XSS code, to be saved as their name in the usr_registration table. The values are then emailed to the the…

  • CVE-2017-17455MedFeb 20, 2018
    risk 0.38cvss 5.9epss 0.01

    Mahara 16.10 before 16.10.7, 17.04 before 17.04.5, and 17.10 before 17.10.2 are vulnerable to being forced, via a man-in-the-middle attack, to interact with Mahara on the HTTP protocol rather than HTTPS even when an SSL certificate is present.

  • CVE-2022-29584MedApr 28, 2022
    risk 0.35cvss 5.4epss 0.01

    Mahara before 20.10.5, 21.04.4, 21.10.2, and 22.04.0 allows stored XSS when a particular Cascading Style Sheets (CSS) class for embedly is used, and JavaScript code is constructed to perform an action.

  • CVE-2022-24111MedFeb 10, 2022
    risk 0.35cvss 5.3epss 0.01

    In Mahara 21.04 before 21.04.3 and 21.10 before 21.10.1, portfolios created in groups that have not been shared with non-group members and portfolios created on the site and institution levels can be viewed without requiring a login if the URL to these portfolios is known.

  • CVE-2021-43265MedNov 2, 2021
    risk 0.35cvss 5.4epss 0.01

    In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, certain tag syntax could be used for XSS, such as via a SCRIPT element.

  • CVE-2019-9709MedMay 7, 2019
    risk 0.35cvss 5.4epss 0.01

    An issue was discovered in Mahara 17.10 before 17.10.8, 18.04 before 18.04.4, and 18.10 before 18.10.1. The collection title is vulnerable to Cross Site Scripting (XSS) due to not escaping it when viewing the collection's SmartEvidence overview page (if that feature is turned…

Page 1 of 3