mahara CVE Vulnerabilities & Metrics

Focus on mahara vulnerabilities and metrics.

Last updated: 16 Apr 2025, 22:25 UTC

About mahara Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with mahara. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total mahara CVEs: 60
Earliest CVE date: 22 Jan 2008, 20:00 UTC
Latest CVE date: 06 Nov 2022, 17:15 UTC

Latest CVE reference: CVE-2022-44544

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 0

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): 0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): 0.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical mahara CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 4.74

Max CVSS: 7.5

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 20
4.0-6.9 72
7.0-8.9 7
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS mahara CVEs

These are the five CVEs with the highest CVSS scores for mahara, sorted by severity first and recency.

All CVEs for mahara

CVE-2022-44544 mahara vulnerability CVSS: 0 06 Nov 2022, 17:15 UTC

Mahara 21.04 before 21.04.7, 21.10 before 21.10.5, 22.04 before 22.04.3, and 22.10 before 22.10.0 potentially allow a PDF export to trigger a remote shell if the site is running on Ubuntu and the flag -dSAFER is not set with Ghostscript.

CVE-2022-42707 mahara vulnerability CVSS: 0 06 Nov 2022, 17:15 UTC

In Mahara 21.04 before 21.04.7, 21.10 before 21.10.5, 22.04 before 22.04.3, and 22.10 before 22.10.0, embedded images are accessible without a sufficient permission check under certain conditions.

CVE-2022-33913 mahara vulnerability CVSS: 4.3 20 Jun 2022, 16:15 UTC

In Mahara 21.04 before 21.04.6, 21.10 before 21.10.4, and 22.04.2, files can sometimes be downloaded through thumb.php with no permission check.

CVE-2022-29585 mahara vulnerability CVSS: 5.0 28 Apr 2022, 16:15 UTC

In Mahara before 20.10.5, 21.04.4, 21.10.2, and 22.04.0, a site using Isolated Institutions is vulnerable if more than ten groups are used. They are all shown from page 2 of the group results list (rather than only being shown for the institution that the viewer is a member of).

CVE-2022-29584 mahara vulnerability CVSS: 3.5 28 Apr 2022, 16:15 UTC

Mahara before 20.10.5, 21.04.4, 21.10.2, and 22.04.0 allows stored XSS when a particular Cascading Style Sheets (CSS) class for embedly is used, and JavaScript code is constructed to perform an action.

CVE-2022-28892 mahara vulnerability CVSS: 6.8 28 Apr 2022, 16:15 UTC

Mahara before 20.10.5, 21.04.4, 21.10.2, and 22.04.0 is vulnerable to Cross Site Request Forgery (CSRF) because randomly generated tokens are too easily guessable.

CVE-2022-24111 mahara vulnerability CVSS: 5.0 10 Feb 2022, 16:15 UTC

In Mahara 21.04 before 21.04.3 and 21.10 before 21.10.1, portfolios created in groups that have not been shared with non-group members and portfolios created on the site and institution levels can be viewed without requiring a login if the URL to these portfolios is known.

CVE-2022-24694 mahara vulnerability CVSS: 4.0 09 Feb 2022, 05:15 UTC

In Mahara 20.10 before 20.10.4, 21.04 before 21.04.3, and 21.10 before 21.10.1, the names of folders in the Files area can be seen by a person not owning the folders. (Only folder names are affected. Neither file names nor file contents are affected.)

CVE-2021-40849 mahara vulnerability CVSS: 7.5 03 Nov 2021, 11:15 UTC

In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, the account associated with a web services token is vulnerable to being exploited and logged into, resulting in information disclosure (at a minimum) and often escalation of privileges.

CVE-2021-40848 mahara vulnerability CVSS: 6.8 03 Nov 2021, 11:15 UTC

In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, exported CSV files could contain characters that a spreadsheet program could interpret as a command, leading to execution of a malicious string locally on a device, aka CSV injection.

CVE-2021-43266 mahara vulnerability CVSS: 4.6 02 Nov 2021, 22:15 UTC

In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, exporting collections via PDF export could lead to code execution via shell metacharacters in a collection name. Additional, in Mahara before 20.10.4, 21.04.3, and 21.10.1, exporting collections via PDF export could cause code execution

CVE-2021-43265 mahara vulnerability CVSS: 3.5 02 Nov 2021, 22:15 UTC

In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, certain tag syntax could be used for XSS, such as via a SCRIPT element.

CVE-2021-43264 mahara vulnerability CVSS: 2.1 02 Nov 2021, 22:15 UTC

In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, adjusting the path component for the page help file allows attackers to bypass the intended access control for HTML files via directory traversal. It replaces the - character with the / character.

CVE-2021-29349 mahara vulnerability CVSS: 4.3 31 Mar 2021, 23:15 UTC

Mahara 20.10 is affected by Cross Site Request Forgery (CSRF) that allows a remote attacker to remove inbox-mail on the server. The application fails to validate the CSRF token for a POST request. An attacker can craft a module/multirecipientnotification/inbox.php pieform_delete_all_notifications request, which leads to removing all messages from a mailbox.

CVE-2020-15907 mahara vulnerability CVSS: 4.3 07 Aug 2020, 20:15 UTC

In Mahara 19.04 before 19.04.6, 19.10 before 19.10.4, and 20.04 before 20.04.1, certain places could execute file or folder names containing JavaScript.

CVE-2020-9387 mahara vulnerability CVSS: 3.5 30 Apr 2020, 13:15 UTC

In Mahara 19.04 before 19.04.5 and 19.10 before 19.10.3, account details are shared in the Elasticsearch results for accounts that are not accessible when the config setting 'Isolated institutions' is turned on.

CVE-2020-9386 mahara vulnerability CVSS: 4.0 09 Mar 2020, 16:15 UTC

In Mahara 18.10 before 18.10.5, 19.04 before 19.04.4, and 19.10 before 19.10.2, file metadata information is disclosed to group members in the Elasticsearch result list despite them not having access to that artefact anymore.

CVE-2020-9282 mahara vulnerability CVSS: 4.0 09 Mar 2020, 14:15 UTC

In Mahara 18.10 before 18.10.5, 19.04 before 19.04.4, and 19.10 before 19.10.2, certain personal information is discoverable inspecting network responses on the 'Edit access' screen when sharing portfolios.

CVE-2012-2237 mahara vulnerability CVSS: 4.3 17 Dec 2019, 18:15 UTC

Multiple cross-site scripting (XSS) vulnerabilities in Mahara 1.4.x before 1.4.3 and 1.5.x before 1.5.2 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) javascript innerHTML as used when generating login forms, (2) links or (3) resources URLs, and (4) the Display name in a user profile.

CVE-2013-1426 mahara vulnerability CVSS: 4.3 07 Nov 2019, 21:15 UTC

Cross-site Scripting (XSS) in Mahara before 1.5.9 and 1.6.x before 1.6.4 allows remote attackers to inject arbitrary web script or HTML via the TinyMCE editor.

CVE-2019-9708 mahara vulnerability CVSS: 4.0 07 May 2019, 17:29 UTC

An issue was discovered in Mahara 17.10 before 17.10.8, 18.04 before 18.04.4, and 18.10 before 18.10.1. A site administrator can suspend the system user (root), causing all users to be locked out from the system.

CVE-2019-9709 mahara vulnerability CVSS: 3.5 07 May 2019, 14:29 UTC

An issue was discovered in Mahara 17.10 before 17.10.8, 18.04 before 18.04.4, and 18.10 before 18.10.1. The collection title is vulnerable to Cross Site Scripting (XSS) due to not escaping it when viewing the collection's SmartEvidence overview page (if that feature is turned on). This can be exploited by any logged-in user.

CVE-2018-11196 mahara vulnerability CVSS: 5.0 01 Jun 2018, 19:29 UTC

Mahara 17.04 before 17.04.8 and 17.10 before 17.10.5 and 18.04 before 18.04.1 can be used as medium to transmit viruses by placing infected files into a Leap2A archive and uploading that to Mahara. In contrast to other ZIP files that are uploaded, ClamAV (when activated) does not check Leap2A archives for viruses, allowing malicious files to be available for download. While files cannot be executed on Mahara itself, Mahara can be used to transfer such files to user computers.

CVE-2018-11195 mahara vulnerability CVSS: 2.1 01 Jun 2018, 19:29 UTC

Mahara 17.04 before 17.04.8 and 17.10 before 17.10.5 and 18.04 before 18.04.1 are vulnerable to the browser "back and refresh" attack. This allows malicious users with physical access to the web browser of a Mahara user, after they have logged in, to potentially gain access to their Mahara credentials.

CVE-2018-11565 mahara vulnerability CVSS: 5.0 30 May 2018, 21:29 UTC

Mahara 17.04 before 17.04.8 and 17.10 before 17.10.5 and 18.04 before 18.04.1 are vulnerable to mentioning the usernames that are already taken by people registered in the system rather than masking that information.

CVE-2018-6182 mahara vulnerability CVSS: 4.3 09 Apr 2018, 20:29 UTC

Mahara 16.10 before 16.10.9 and 17.04 before 17.04.7 and 17.10 before 17.10.4 are vulnerable to bad input when TinyMCE is bypassed by POST packages. Therefore, Mahara should not rely on TinyMCE's code stripping alone but also clean input on the server / PHP side as one can create own packets of POST data containing bad content with which to hit the server.

CVE-2017-17455 mahara vulnerability CVSS: 4.3 20 Feb 2018, 22:29 UTC

Mahara 16.10 before 16.10.7, 17.04 before 17.04.5, and 17.10 before 17.10.2 are vulnerable to being forced, via a man-in-the-middle attack, to interact with Mahara on the HTTP protocol rather than HTTPS even when an SSL certificate is present.

CVE-2017-17454 mahara vulnerability CVSS: 3.5 20 Feb 2018, 22:29 UTC

Mahara 16.10 before 16.10.7 and 17.04 before 17.04.5 and 17.10 before 17.10.2 have a Cross Site Scripting (XSS) vulnerability when a user enters invalid UTF-8 characters. These are now going to be discarded in Mahara along with NULL characters and invalid Unicode characters. Mahara will also avoid direct $_GET and $_POST usage where possible, and instead use param_exists() and the correct param_*() function to fetch the expected value.

CVE-2017-1000141 mahara vulnerability CVSS: 6.4 30 Jan 2018, 19:29 UTC

An issue was discovered in Mahara before 18.10.0. It mishandled user requests that could discontinue a user's ability to maintain their own account (changing username, changing primary email address, deleting account). The correct behavior was to either prompt them for their password and/or send a warning to their primary email address.

CVE-2017-1000171 mahara vulnerability CVSS: 5.0 03 Nov 2017, 18:29 UTC

Mahara Mobile before 1.2.1 is vulnerable to passwords being sent to the Mahara access log in plain text.

CVE-2017-1000157 mahara vulnerability CVSS: 3.5 03 Nov 2017, 18:29 UTC

Mahara 15.04 before 15.04.13 and 16.04 before 16.04.7 and 16.10 before 16.10.4 and 17.04 before 17.04.2 are vulnerable to recording plain text passwords in the event_log table during the user creation process if full event logging was turned on.

CVE-2017-1000156 mahara vulnerability CVSS: 5.5 03 Nov 2017, 18:29 UTC

Mahara 15.04 before 15.04.9 and 15.10 before 15.10.5 and 16.04 before 16.04.3 are vulnerable to a group's configuration page being editable by any group member even when they didn't have the admin role.

CVE-2017-1000155 mahara vulnerability CVSS: 4.0 03 Nov 2017, 18:29 UTC

Mahara 15.04 before 15.04.8 and 15.10 before 15.10.4 and 16.04 before 16.04.2 are vulnerable to profile pictures being accessed without any access control checks consequently allowing any of a user's uploaded profile pictures to be viewable by anyone, whether or not they were currently selected as the "default" or used in any pages.

CVE-2017-1000154 mahara vulnerability CVSS: 7.5 03 Nov 2017, 18:29 UTC

Mahara 15.04 before 15.04.8 and 15.10 before 15.10.4 and 16.04 before 16.04.2 are vulnerable to some authentication methods, which do not use Mahara's built-in login form, still allowing users to log in even if their institution was expired or suspended.

CVE-2017-1000153 mahara vulnerability CVSS: 7.5 03 Nov 2017, 18:29 UTC

Mahara 15.04 before 15.04.10 and 15.10 before 15.10.6 and 16.04 before 16.04.4 are vulnerable to incorrect access control after the password reset link is sent via email and then user changes default email, Mahara fails to invalidate old link.Consequently the link in email can be used to gain access to the user's account.

CVE-2017-1000152 mahara vulnerability CVSS: 7.5 03 Nov 2017, 18:29 UTC

Mahara 15.04 before 15.04.7 and 15.10 before 15.10.3 running PHP 5.3 are vulnerable to one user being logged in as another user on a separate computer as the same session ID is served. This situation can occur when a user takes an action that forces another user to be logged out of Mahara, such as an admin changing another user's account settings.

CVE-2017-1000151 mahara vulnerability CVSS: 5.0 03 Nov 2017, 18:29 UTC

Mahara 15.04 before 15.04.9 and 15.10 before 15.10.5 and 16.04 before 16.04.3 are vulnerable to passwords or other sensitive information being passed by unusual parameters to end up in an error log.

CVE-2017-1000150 mahara vulnerability CVSS: 6.5 03 Nov 2017, 18:29 UTC

Mahara 15.04 before 15.04.7 and 15.10 before 15.10.3 are vulnerable to prevent session IDs from being regenerated on login or logout. This makes users of the site more vulnerable to session fixation attacks.

CVE-2017-1000149 mahara vulnerability CVSS: 3.5 03 Nov 2017, 18:29 UTC

Mahara 1.10 before 1.10.9 and 15.04 before 15.04.6 and 15.10 before 15.10.2 are vulnerable to XSS due to window.opener (target="_blank" and window.open())

CVE-2017-1000148 mahara vulnerability CVSS: 6.5 03 Nov 2017, 18:29 UTC

Mahara 15.04 before 15.04.8 and 15.10 before 15.10.4 and 16.04 before 16.04.2 are vulnerable to PHP code execution as Mahara would pass portions of the XML through the PHP "unserialize()" function when importing a skin from an XML file.

CVE-2017-1000147 mahara vulnerability CVSS: 6.0 03 Nov 2017, 18:29 UTC

Mahara 1.9 before 1.9.8 and 1.10 before 1.10.6 and 15.04 before 15.04.3 are vulnerable to perform a cross-site request forgery (CSRF) attack on the uploader contained in Mahara's filebrowser widget. This could allow an attacker to trick a Mahara user into unknowingly uploading malicious files into their Mahara account.

CVE-2017-1000146 mahara vulnerability CVSS: 3.5 03 Nov 2017, 18:29 UTC

Mahara 1.9 before 1.9.7 and 1.10 before 1.10.5 and 15.04 before 15.04.2 are vulnerable to the arbitrary execution of Javascript in the browser of a logged-in user because the title of the portfolio page was not being properly escaped in the AJAX script that updates the Add/remove watchlist link on artefact detail pages.

CVE-2017-1000145 mahara vulnerability CVSS: 4.0 03 Nov 2017, 18:29 UTC

Mahara 1.9 before 1.9.7 and 1.10 before 1.10.5 and 15.04 before 15.04.2 are vulnerable to anonymous comments being able to be placed on artefact detail pages even when the site administrator had disallowed anonymous comments.

CVE-2017-1000144 mahara vulnerability CVSS: 3.5 03 Nov 2017, 18:29 UTC

Mahara 1.9 before 1.9.6 and 1.10 before 1.10.4 and 15.04 before 15.04.1 are vulnerable to a site admin or institution admin being able to place HTML and Javascript into an institution display name, which will be displayed to other users unescaped on some Mahara system pages.

CVE-2017-1000143 mahara vulnerability CVSS: 4.0 03 Nov 2017, 18:29 UTC

Mahara 1.8 before 1.8.7 and 1.9 before 1.9.5 and 1.10 before 1.10.3 and 15.04 before 15.04.0 are vulnerable to users receiving watchlist notifications about pages they do not have access to anymore.

CVE-2017-1000142 mahara vulnerability CVSS: 5.5 03 Nov 2017, 18:29 UTC

Mahara 1.8 before 1.8.7 and 1.9 before 1.9.5 and 1.10 before 1.10.3 and 15.04 before 15.04.0 are vulnerable to users being able to delete their submitted page through URL manipulation.

CVE-2017-1000140 mahara vulnerability CVSS: 3.5 03 Nov 2017, 18:29 UTC

Mahara 1.8 before 1.8.7 and 1.9 before 1.9.5 and 1.10 before 1.10.3 and 15.04 before 15.04.0 are vulnerable to a maliciously created .xml file that can have its code executed when user tries to download the file.

CVE-2017-1000139 mahara vulnerability CVSS: 6.0 03 Nov 2017, 18:29 UTC

Mahara 1.8 before 1.8.7 and 1.9 before 1.9.5 and 1.10 before 1.10.3 and 15.04 before 15.04.0 are vulnerable to server-side request forgery attacks as not all processes of curl redirects are checked against a white or black list. Employing SafeCurl will prevent issues.

CVE-2017-1000138 mahara vulnerability CVSS: 3.5 03 Nov 2017, 18:29 UTC

Mahara 1.10 before 1.10.0 and 15.04 before 15.04.0 are vulnerable to possible cross site scripting when dragging/dropping files into a collection if the file has Javascript code in its title.

CVE-2017-1000137 mahara vulnerability CVSS: 3.5 03 Nov 2017, 18:29 UTC

Mahara 1.10 before 1.10.0 and 15.04 before 15.04.0 are vulnerable to possible cross site scripting when adding a text block to a page via the keyboard (rather than drag and drop).

CVE-2017-1000136 mahara vulnerability CVSS: 4.3 03 Nov 2017, 18:29 UTC

Mahara 1.8 before 1.8.6 and 1.9 before 1.9.4 and 1.10 before 1.10.1 and 15.04 before 15.04.0 are vulnerable to old sessions not being invalidated after a password change.

CVE-2017-1000135 mahara vulnerability CVSS: 4.0 03 Nov 2017, 18:29 UTC

Mahara 1.8 before 1.8.7 and 1.9 before 1.9.5 and 1.10 before 1.10.3 and 15.04 before 15.04.0 are vulnerable as logged-in users can stay logged in after the institution they belong to is suspended.

CVE-2017-1000134 mahara vulnerability CVSS: 6.5 03 Nov 2017, 18:29 UTC

Mahara 1.8 before 1.8.6 and 1.9 before 1.9.4 and 1.10 before 1.10.1 and 15.04 before 15.04.0 are vulnerable because group members can lose access to the group files they uploaded if another group member changes the access permissions on them.

CVE-2017-1000133 mahara vulnerability CVSS: 5.0 03 Nov 2017, 18:29 UTC

Mahara 15.04 before 15.04.8 and 15.10 before 15.10.4 and 16.04 before 16.04.2 are vulnerable to a user - in some circumstances causing another user's artefacts to be included in a Leap2a export of their own pages.

CVE-2017-1000132 mahara vulnerability CVSS: 3.5 03 Nov 2017, 18:29 UTC

Mahara 1.8 before 1.8.7 and 1.9 before 1.9.5 and 1.10 before 1.10.3 and 15.04 before 15.04.0 are vulnerable to a maliciously created .swf files that can have its code executed when a user tries to download the file.

CVE-2017-1000131 mahara vulnerability CVSS: 4.0 03 Nov 2017, 18:29 UTC

Mahara 15.04 before 15.04.8 and 15.10 before 15.10.4 and 16.04 before 16.04.2 are vulnerable to users staying logged in to their Mahara account even when they have been logged out of Moodle (when using MNet) as Mahara did not properly implement one of the MNet SSO API functions.

CVE-2017-15273 mahara vulnerability CVSS: 3.5 31 Oct 2017, 18:29 UTC

Mahara 15.04 before 15.04.15, 16.04 before 16.04.9, 16.10 before 16.10.6, and 17.04 before 17.04.4 are vulnerable to a user submitting a potential dangerous payload, e.g., XSS code, to be saved as titles in internal artefacts.

CVE-2017-14752 mahara vulnerability CVSS: 3.5 31 Oct 2017, 18:29 UTC

Mahara 15.04 before 15.04.15, 16.04 before 16.04.9, 16.10 before 16.10.6, and 17.04 before 17.04.4 are vulnerable to a user submitting a potential dangerous payload, e.g., XSS code, to be saved as their first name, last name, or display name in the profile fields that can cause issues such as escalation of privileges or unknown execution of malicious code when replying to messages in Mahara.

CVE-2017-14163 mahara vulnerability CVSS: 6.5 31 Oct 2017, 18:29 UTC

An issue was discovered in Mahara before 15.04.14, 16.x before 16.04.8, 16.10.x before 16.10.5, and 17.x before 17.04.3. When one closes the browser without logging out of Mahara, the value in the usr_session table is not removed. If someone were to open a browser, visit the Mahara site, and adjust the 'mahara' cookie to the old value, they can get access to the user's account.

CVE-2017-9551 mahara vulnerability CVSS: 4.3 25 Sep 2017, 16:29 UTC

Mahara 15.04 before 15.04.14 and 16.04 before 16.04.8 and 16.10 before 16.10.5 and 17.04 before 17.04.3 are vulnerable to a user submitting potential dangerous payload, e.g. XSS code, to be saved as their name in the usr_registration table. The values are then emailed to the the user and administrator and if accepted become part of the new user's account.

CVE-2013-4432 mahara vulnerability CVSS: 4.0 19 May 2014, 14:55 UTC

Mahara before 1.5.13, 1.6.x before 1.6.8, and 1.7.x before 1.7.4 does not properly restrict access to folders, which allows remote authenticated users to read arbitrary folders (1) by leveraging an active folder tab loaded before permissions were removed or (2) via the folder parameter to artefact/file/groupfiles.php.

CVE-2013-4431 mahara vulnerability CVSS: 5.5 19 May 2014, 14:55 UTC

Mahara before 1.5.12, 1.6.x before 1.6.7, and 1.7.x before 1.7.3 does not properly prevent access to blocks, which allows remote authenticated users to modify arbitrary blocks via the bock id in an edit request.

CVE-2013-4430 mahara vulnerability CVSS: 4.3 19 May 2014, 14:55 UTC

Cross-site scripting (XSS) vulnerability in Mahara before 1.5.12, 1.6.x before 1.6.7, and 1.7.x before 1.7.3 allows remote attackers to inject arbitrary web script or HTML via the Host header to lib/web.php.

CVE-2013-4429 mahara vulnerability CVSS: 4.0 19 May 2014, 14:55 UTC

Mahara before 1.5.12, 1.6.x before 1.6.7, and 1.7.x before 1.7.3 does not properly restrict access to artefacts, which allows remote authenticated users to read arbitrary artefacts via the (1) artefact id in an upload action when creating a journal or (2) instconf_artefactid_selected[ID] parameter in an upload action when editing a block.

CVE-2012-6037 mahara vulnerability CVSS: 4.3 24 Nov 2012, 20:55 UTC

Multiple cross-site scripting (XSS) vulnerabilities in Mahara 1.4.x before 1.4.5 and 1.5.x before 1.5.4, and other versions including 1.2, allow remote attackers to inject arbitrary web script or HTML via a CSV header with "unknown fields," which are not properly handled in error messages in the (1) bulk user, (2) group, and (3) group member upload capabilities. NOTE: this issue was originally part of CVE-2012-2243, but that ID was SPLIT due to different issues by different researchers.

CVE-2012-2253 mahara vulnerability CVSS: 4.3 24 Nov 2012, 20:55 UTC

Cross-site scripting (XSS) vulnerability in group/members.php in Mahara 1.5.x before 1.5.7 and 1.6.x before 1.6.2 allows remote attackers to inject arbitrary web script or HTML via the query parameter.

CVE-2012-2247 mahara vulnerability CVSS: 4.3 24 Nov 2012, 20:55 UTC

Cross-site scripting (XSS) vulnerability in Mahara 1.4.x before 1.4.5 and 1.5.x before 1.5.4 allows remote attackers to inject arbitrary web script or HTML via vectors related to artefact/file/ and a crafted SVG file.

CVE-2012-2246 mahara vulnerability CVSS: 6.8 24 Nov 2012, 20:55 UTC

Mahara 1.4.x before 1.4.5 and 1.5.x before 1.5.4 allows remote attackers to conduct clickjacking attacks to delete arbitrary users and bypass CSRF protection via account/delete.php.

CVE-2012-2244 mahara vulnerability CVSS: 6.0 24 Nov 2012, 20:55 UTC

Mahara 1.4.x before 1.4.5 and 1.5.x before 1.5.4 allows remote authenticated administrators to execute arbitrary programs by modifying the path to clamav. NOTE: this can be exploited without authentication by leveraging CVE-2012-2243.

CVE-2012-2243 mahara vulnerability CVSS: 4.3 24 Nov 2012, 20:55 UTC

Cross-site scripting (XSS) vulnerability in Mahara 1.4.x before 1.4.5 and 1.5.x before 1.5.4 allows remote attackers to inject arbitrary web script or HTML by uploading an XML file with the xhtml extension, which is rendered inline as script. NOTE: this can be leveraged with CVE-2012-2244 to execute arbitrary code without authentication, as demonstrated by modifying the clamav path.

CVE-2012-2239 mahara vulnerability CVSS: 6.4 24 Nov 2012, 20:55 UTC

Mahara 1.4.x before 1.4.4 and 1.5.x before 1.5.3 allows remote attackers to read arbitrary files or create TCP connections via an XML external entity (XXE) injection attack, as demonstrated by reading config.php.

CVE-2012-2351 mahara vulnerability CVSS: 5.0 12 Jul 2012, 20:55 UTC

The default configuration of the auth/saml plugin in Mahara before 1.4.2 sets the "Match username attribute to Remote username" option to false, which allows remote SAML IdP servers to spoof users of other SAML IdP servers by using the same internal username.

CVE-2011-4118 mahara vulnerability CVSS: 6.0 15 Nov 2011, 03:57 UTC

Mahara before 1.4.1, when MNet (aka the Moodle network feature) is used, allows remote authenticated users to gain privileges via a jump to an XMLRPC target.

CVE-2011-2774 mahara vulnerability CVSS: 4.0 15 Nov 2011, 03:57 UTC

The "Reply to message" feature in Mahara 1.3.x and 1.4.x before 1.4.1 allows remote authenticated users to read the messages of a different user via a modified replyto parameter.

CVE-2011-2773 mahara vulnerability CVSS: 6.8 15 Nov 2011, 03:57 UTC

Cross-site request forgery (CSRF) vulnerability in Mahara before 1.4.1 allows remote attackers to hijack the authentication of administrators for requests that add a user to an institution.

CVE-2011-2772 mahara vulnerability CVSS: 5.0 15 Nov 2011, 03:57 UTC

The get_dataroot_image_path function in lib/file.php in Mahara before 1.4.1 does not properly validate uploaded image files, which allows remote attackers to cause a denial of service (memory consumption) via a (1) large or (2) invalid image.

CVE-2011-2771 mahara vulnerability CVSS: 4.3 15 Nov 2011, 03:57 UTC

Multiple cross-site scripting (XSS) vulnerabilities in Mahara before 1.4.1 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) URI attributes and (2) the External Feed component, as demonstrated by the guid element in an RSS feed.

CVE-2011-1406 mahara vulnerability CVSS: 4.3 13 May 2011, 22:55 UTC

Mahara before 1.3.6 does not properly handle an https URL in the wwwroot configuration setting, which makes it easier for user-assisted remote attackers to obtain credentials by sniffing the network at a time when an http URL is used for a login.

CVE-2011-1405 mahara vulnerability CVSS: 3.5 13 May 2011, 22:55 UTC

Cross-site scripting (XSS) vulnerability in Mahara before 1.3.6 allows remote authenticated users to inject arbitrary web script or HTML via vectors associated with HTML e-mail messages, related to artefact/comment/lib.php and interaction/forum/lib.php.

CVE-2011-1404 mahara vulnerability CVSS: 4.0 13 May 2011, 22:55 UTC

Mahara before 1.3.6 does not properly restrict the data in responses to AJAX calls, which allows remote authenticated users to obtain sensitive information via a request associated with (1) blocktype/myfriends/myfriends.json.php, (2) json/usersearch.php, (3) group/membersearchresults.json.php, or (4) json/friendsearch.php, as demonstrated by information about friends and e-mail addresses.

CVE-2011-1403 mahara vulnerability CVSS: 6.8 13 May 2011, 22:55 UTC

Cross-site request forgery (CSRF) vulnerability in the pieforms implementation in Mahara before 1.3.6 allows remote attackers to hijack the authentication of arbitrary users for requests to any form, related to inappropriate regeneration of session keys.

CVE-2011-1402 mahara vulnerability CVSS: 6.5 13 May 2011, 22:55 UTC

Mahara before 1.3.6 allows remote authenticated users to bypass intended access restrictions, and suspend a user account, edit a view, visit a view, edit a plan artefact, read a plans block, read a plan artefact, edit a blog, read a blog block, read a blog artefact, or access a block, via a request associated with (1) admin/users/search.json.php, (2) view/newviewtoken.json.php, (3) lib/mahara.php, (4) artefact/plans/tasks.json.php, (5) artefact/plans/viewtasks.json.php, (6) artefact/blog/view/index.json.php, (7) artefact/blog/posts.json.php, or (8) blocktype/myfriends/myfriends.json.php, related to incorrect privilege enforcement, a missing user id check, and incorrect enforcement of the Overriding Start/Stop Dates setting.

CVE-2011-0440 mahara vulnerability CVSS: 5.8 28 Mar 2011, 16:55 UTC

Cross-site request forgery (CSRF) vulnerability in Mahara 1.2.x before 1.2.7 and 1.3.x before 1.3.4 allows remote attackers to hijack the authentication of arbitrary users for requests that delete blogs.

CVE-2011-0439 mahara vulnerability CVSS: 4.3 28 Mar 2011, 16:55 UTC

Cross-site scripting (XSS) vulnerability in Mahara 1.2.x before 1.2.7 and 1.3.x before 1.3.4 allows remote attackers to inject arbitrary web script or HTML via the Pieforms select box.

CVE-2010-3871 mahara vulnerability CVSS: 4.3 09 Nov 2010, 21:00 UTC

Cross-site scripting (XSS) vulnerability in blocktype/groupviews/theme/raw/groupviews.tpl in Mahara before 1.3.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: some of these details are obtained from third party information.

CVE-2010-2479 mahara vulnerability CVSS: 4.3 06 Jul 2010, 17:17 UTC

Cross-site scripting (XSS) vulnerability in HTML Purifier before 4.1.1, as used in Mahara and other products, when the browser is Internet Explorer, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2010-1670 mahara vulnerability CVSS: 7.5 06 Jul 2010, 17:17 UTC

Mahara before 1.0.15, 1.1.x before 1.1.9, and 1.2.x before 1.2.5 has improper configuration options for authentication plugins associated with logins that use the single sign-on (SSO) functionality, which allows remote attackers to bypass authentication via an empty password. NOTE: some of these details are obtained from third party information.

CVE-2010-1669 mahara vulnerability CVSS: 7.5 06 Jul 2010, 17:17 UTC

SQL injection vulnerability in Mahara 1.1.x before 1.1.9 and 1.2.x before 1.2.5 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

CVE-2010-1668 mahara vulnerability CVSS: 6.8 06 Jul 2010, 17:17 UTC

Multiple cross-site request forgery (CSRF) vulnerabilities in Mahara before 1.0.15, 1.1.x before 1.1.9, and 1.2.x before 1.2.5 allow remote attackers to hijack the authentication of unspecified victims via unknown vectors.

CVE-2010-1667 mahara vulnerability CVSS: 4.3 06 Jul 2010, 17:17 UTC

Multiple cross-site scripting (XSS) vulnerabilities in Mahara before 1.0.15, 1.1.x before 1.1.9, and 1.2.x before 1.2.5 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2010-0400 mahara vulnerability CVSS: 7.5 07 Apr 2010, 15:30 UTC

SQL injection vulnerability in lib/user.php in mahara 1.0.4 allows remote attackers to execute arbitrary SQL commands via a username.

CVE-2009-3299 mahara vulnerability CVSS: 4.3 03 Nov 2009, 16:30 UTC

Cross-site scripting (XSS) vulnerability in the resume blocktype in Mahara before 1.0.13, and 1.1.x before 1.1.7, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2009-3298 mahara vulnerability CVSS: 6.5 03 Nov 2009, 16:30 UTC

Mahara before 1.0.13, and 1.1.x before 1.1.7, allows remote authenticated institution administrators to reset a site administrator password via unspecified vectors.

CVE-2009-2171 mahara vulnerability CVSS: 4.0 23 Jun 2009, 16:30 UTC

Mahara 1.1 before 1.1.5 does not apply permission checks when saving a view that contains artefacts, which allows remote authenticated users to read another user's artefact.

CVE-2009-2170 mahara vulnerability CVSS: 4.3 23 Jun 2009, 16:30 UTC

Multiple cross-site scripting (XSS) vulnerabilities in Mahara 1.0 before 1.0.12 and 1.1 before 1.1.5 allow remote attackers to inject arbitrary web script or HTML via unknown vectors.

CVE-2009-0664 mahara vulnerability CVSS: 4.3 23 Apr 2009, 17:30 UTC

Multiple cross-site scripting (XSS) vulnerabilities in Mahara 1.0.x before 1.0.11 and 1.1.x before 1.1.3 allow remote attackers to inject arbitrary web script or HTML via (1) the introduction field in a user profile or (2) an arbitrary text block in a user view.

CVE-2009-0660 mahara vulnerability CVSS: 4.3 11 Mar 2009, 14:19 UTC

Multiple cross-site scripting (XSS) vulnerabilities in Mahara 1.0 before 1.0.10 and 1.1 before 1.1.2 allow remote attackers to inject arbitrary web script or HTML via a (1) profile and (2) blog, a different vulnerability than CVE-2009-0487.

CVE-2009-0487 mahara vulnerability CVSS: 4.3 09 Feb 2009, 20:30 UTC

Cross-site scripting (XSS) vulnerability in Mahara before 1.0.9 allows remote attackers to inject arbitrary web script or HTML via a crafted forum post.

CVE-2008-0381 mahara vulnerability CVSS: 4.3 22 Jan 2008, 20:00 UTC

Unspecified vulnerability in Mahara before 0.9.1 has unknown impact and remote attack vectors, probably related to cross-site scripting (XSS) in uploaded files.