Known Vulnerabilities for products from Mahara

Listed below are 20 of the newest known vulnerabilities associated with the vendor "Mahara".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2025-61872 json Not Provided 2026-04-24 2026-04-24
CVE-2025-59308 json Not Provided 2026-04-24 2026-04-24
CVE-2022-44544 json Mahara 21.04 before 21.04.7, 21.10 before 21.10.5, 22.04 before 22.04.3, and 22.10 before 22.10.0 potentially allow a PDF exp... 9.8 - CRITICAL 2022-11-06 2022-11-10
CVE-2022-42707 json In Mahara 21.04 before 21.04.7, 21.10 before 21.10.5, 22.04 before 22.04.3, and 22.10 before 22.10.0, embedded images are acc... 7.5 - HIGH 2022-11-06 2022-11-08
CVE-2022-33913 json In Mahara 21.04 before 21.04.6, 21.10 before 21.10.4, and 22.04.2, files can sometimes be downloaded through thumb.php with n... 7.5 - HIGH 2022-06-20 2023-08-08
CVE-2022-29585 json In Mahara before 20.10.5, 21.04.4, 21.10.2, and 22.04.0, a site using Isolated Institutions is vulnerable if more than ten gr... 7.5 - HIGH 2022-04-28 2022-05-09
CVE-2022-29584 json Mahara before 20.10.5, 21.04.4, 21.10.2, and 22.04.0 allows stored XSS when a particular Cascading Style Sheets (CSS) class f... 5.4 - MEDIUM 2022-04-28 2022-05-06
CVE-2022-28892 json Mahara before 20.10.5, 21.04.4, 21.10.2, and 22.04.0 is vulnerable to Cross Site Request Forgery (CSRF) because randomly gene... 8.8 - HIGH 2022-04-28 2023-01-30
CVE-2022-24694 json In Mahara 20.10 before 20.10.4, 21.04 before 21.04.3, and 21.10 before 21.10.1, the names of folders in the Files area can be... 4.3 - MEDIUM 2022-02-09 2022-02-11
CVE-2022-24111 json In Mahara 21.04 before 21.04.3 and 21.10 before 21.10.1, portfolios created in groups that have not been shared with non-grou... 5.3 - MEDIUM 2022-02-10 2022-02-23
CVE-2021-43266 json In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, exporting collections via PDF export could lead to code execution vi... 7.3 - HIGH 2021-11-02 2022-05-03
CVE-2021-43265 json In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, certain tag syntax could be used for XSS, such as via a SCRIPT eleme... 5.4 - MEDIUM 2021-11-02 2021-11-09
CVE-2021-43264 json In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, adjusting the path component for the page help file allows attackers... 3.3 - LOW 2021-11-02 2021-11-09
CVE-2021-40849 json In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, the account associated with a web services token is vulnerable to be... 9.8 - CRITICAL 2021-11-03 2021-11-05
CVE-2021-40848 json In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, exported CSV files could contain characters that a spreadsheet progr... 7.8 - HIGH 2021-11-03 2021-11-05
CVE-2021-29349 json Mahara 20.10 is affected by Cross Site Request Forgery (CSRF) that allows a remote attacker to remove inbox-mail on the serve... 6.5 - MEDIUM 2021-03-31 2021-04-07
CVE-2020-15907 json In Mahara 19.04 before 19.04.6, 19.10 before 19.10.4, and 20.04 before 20.04.1, certain places could execute file or folder n... 6.1 - MEDIUM 2020-08-07 2020-08-12
CVE-2020-9387 json In Mahara 19.04 before 19.04.5 and 19.10 before 19.10.3, account details are shared in the Elasticsearch results for accounts... 4.3 - MEDIUM 2020-04-30 2020-05-12
CVE-2020-9386 json In Mahara 18.10 before 18.10.5, 19.04 before 19.04.4, and 19.10 before 19.10.2, file metadata information is disclosed to gro... 4.3 - MEDIUM 2020-03-09 2022-10-07
CVE-2020-9282 json In Mahara 18.10 before 18.10.5, 19.04 before 19.04.4, and 19.10 before 19.10.2, certain personal information is discoverable ... 6.5 - MEDIUM 2020-03-09 2020-03-09

Known software with vulnerabilities from Mahara

Type Vendor Product Version
ApplicationMaharaMahara0.9.0
ApplicationMaharaMahara Mobile1.2.0

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report