Gibbonedu
Gibbonedu Gibbon: vulnerabilidades y CVE
Gibbonedu Gibbon tiene 17 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE17
Últimos 12 meses1
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-97864 | Media (5.5) | 0.73% | — | 25 sept 2026 | A vulnerability has been found in GibbonEdu Gibbon up to 30.0.01. The affected element is the function makeBlock of the file modules/Planner/units_add_blockAjax.php of the component Unit Planner. The manipulation of the… |
| CVE-2025-26211 | Alta (8.8) | 0.18% | — | 27 may 2025 | Gibbon before 29.0.00 allows CSRF. |
| CVE-2024-51337 | Baja (3.5) | 0.61% | — | 21 nov 2024 | Cross Site Scripting vulnerability in Gibbon before v.27.0.01 and fixed in v.28.0.00 allows a remote attacker to obtain sensitive information via the email parameter found in /Gibbon/modules/User… |
| CVE-2024-34831 | Media (6.1) | 0.84% | — | 10 sept 2024 | cross-site scripting (XSS) vulnerability in Gibbon Core v26.0.00 allows an attacker to execute arbitrary code via the imageLink parameter in the library_manage_catalog_editProcess.php component. |
| CVE-2024-24724 | Crítica (9.8) | 26% | — | 3 abr 2024 | Gibbon through 26.0.00 allows /modules/School%20Admin/messengerSettings.php Server Side Template Injection leading to Remote Code Execution because input is passed to the Twig template engine (messengerSettings.php)… |
| CVE-2024-24725 | Alta (8.8) | 51% | — | 23 mar 2024 | Gibbon through 26.0.00 allows remote authenticated users to conduct PHP deserialization attacks via columnOrder in a POST request to the modules/System%20Admin/import_run.php&type=externalAssessment&step=4 URI. |
| CVE-2023-45881 | Media (6.1) | 0.50% | — | 14 nov 2023 | GibbonEdu Gibbon through version 25.0.0 allows /modules/Planner/resources_addQuick_ajaxProcess.php file upload with resultant XSS. The imageAsLinks parameter must be set to Y to return HTML code. The filename attribute… |
| CVE-2023-45880 | Alta (7.2) | 1.2% | — | 14 nov 2023 | GibbonEdu Gibbon through version 25.0.0 allows Directory Traversal via the report template builder. An attacker can create a new Asset Component. The templateFileDestination parameter can be set to an arbitrary pathname… |
| CVE-2023-45879 | Media (5.4) | 0.46% | — | 14 nov 2023 | GibbonEdu Gibbon version 25.0.0 allows HTML Injection via an IFRAME element to the Messager component. |
| CVE-2023-45878 | Crítica (9.8) | 63% | — | 14 nov 2023 | GibbonEdu Gibbon version 25.0.1 and before allows Arbitrary File Write because rubrics_visualise_saveAjax.phps does not require authentication. The endpoint accepts the img, path, and gibbonPersonID parameters. The img… |
| CVE-2023-34599 | Media (6.1) | 1.9% | — | 29 jun 2023 | Multiple Cross-Site Scripting (XSS) vulnerabilities have been identified in Gibbon v25.0.0, which enable attackers to execute arbitrary Javascript code. |
| CVE-2023-34598 | Crítica (9.8) | 47% | — | 29 jun 2023 | Gibbon v25.0.0 is vulnerable to a Local File Inclusion (LFI) where it's possible to include the content of several files present in the installation folder in the server's response. |
| CVE-2022-27305 | Alta (8.8) | 0.92% | — | 25 may 2022 | Gibbon v23 does not generate a new session ID cookie after a user authenticates, making the application vulnerable to session fixation. |
| CVE-2022-23871 | Media (5.4) | 0.62% | — | 3 feb 2022 | Multiple cross-site scripting (XSS) vulnerabilities in the component outcomes_addProcess.php of Gibbon CMS v22.0.01 allow attackers to execute arbitrary web scripts or HTML via a crafted payload insterted into the name,… |
| CVE-2022-22868 | Media (4.8) | 0.86% | — | 28 ene 2022 | Gibbon CMS v22.0.01 was discovered to contain a cross-site scripting (XSS) vulnerability, that allows attackers to inject arbitrary script via name parameters. |
| CVE-2021-40214 | Media (5.4) | 0.74% | — | 13 sept 2021 | Gibbon v22.0.00 suffers from a stored XSS vulnerability within the wall messages component. |
| CVE-2021-40492 | Media (6.1) | 2.3% | — | 3 sept 2021 | A reflected XSS vulnerability exists in multiple pages in version 22 of the Gibbon application that allows for arbitrary execution of JavaScript (gibbonCourseClassID, gibbonPersonID, subpage, currentDate, or allStudents… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.