CVE Feed

    Dashboard / CVE / CVE-2026-33402

    CVE-2026-33402

    Sakai is a Collaboration and Learning Environment (CLE). In versions 23.0 through 23.4 and 25.0 through 25.1, group titles and description can contain cross-site scripting scripts. The patch is included in releases 25.2 and 23.5. As a workaround, one can check the SAKAI_SITE_GROUP table for titles and descriptions that contain this info.

    Published:Mar 26, 2026
    Last Modified:Mar 31, 2026
    EPS:Mar 26, 2026
    EPSS Score:0.00047
    CVSS Score:6.1

    Affected Products

    Vendor
    Sakailms
    Product
    Sakai
    Vendor
    Sakaiproject
    Product
    Sakai

    Exploits

    No exploit reference

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High