25
I Use This!
Inactive
Analyzed about 11 hours ago. based on code collected 1 day ago.
 

Security

Vulnerabilities per Version

Learn more about BDSAs
 
 

Major Versions

1yr
3yr
5yr
10yr
All
click and drag to zoom
 
 
Security Vulnerabilities for Version:
Severities:
Type
Identifier Related Record Severity Date Published Description Versions Affected
CVE-2025-29992 BDSA-2025-9921 High Aug 26, 2025 Mahara before 24.04.9 exposes database connection information if the database becomes unreachable, e.g., due to the database server being temporarily d more...
24.04, 23.04, 22.04.3_RELEASE, 21.04.7_RELEASE, 22.10.0_RELEASE, 21.10.5_RELEASE, 22.10, 21.10.4_RELEASE, 21.04.6_RELEASE, 22.04.2_RELEASE
BDSA-2025-9933 Medium Aug 27, 2025 Mahara is vulnerable to cross-site scripting (XSS) due to improper handling of file names containing JavaScript code in the filebrowser system. This co more...
BDSA-2025-9932 Medium Aug 27, 2025 Mahara is vulnerable to unauthorized file access due to improper validation of export download URLs. This could allow an attacker to download files the more...
BDSA-2025-9929 High Aug 27, 2025 Mahara is vulnerable to escalation of privileges due to issues in the Learning Tools Interoperability (LTI) login functionality. This could allow an at more...
BDSA-2025-9928 Low Aug 27, 2025 Mahara is vulnerable to information disclosure due to improper access controls in the `Current submissions` page functionality. This could allow an att more...
BDSA-2025-9923 Medium Aug 27, 2025 Mahara is vulnerable to cross-site scripting (XSS) due to improper handling of the `link` attribute in external RSS feed XML. This could allow an attac more...
BDSA-2025-9871 High Aug 26, 2025 Mahara contains a stored cross-site scripting (XSS) vulnerability due to improper sanitization of the `About`, `Contact`, and `Help` pages. An attacker more...