« Back to list

Mojoomla

Mojoomla School Management: vulnerabilities and CVEs

Mojoomla School Management has 9 published vulnerabilities, 2 of them in the last 12 months. 2 are rated critical and 0 are listed by CISA as actively exploited.

CVEs9
Last 12 months2
Critical2
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2025-15656High (8.8)0.23%—Jun 3, 2026
Incorrect Privilege Assignment vulnerability in Mojoomla School Management allows Privilege Escalation. This issue affects School Management: from n/a through 93.2.0.
CVE-2025-15655High (7.6)0.23%—Jun 3, 2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mojoomla School Management allows SQL Injection. This issue affects School Management: from n/a through 93.2.0.
CVE-2025-31100Critical (9.9)0.37%—Aug 31, 2025
Unrestricted Upload of File with Dangerous Type vulnerability in Mojoomla School Management allows Upload a Web Shell to a Web Server.This issue affects School Management: from n/a through 1.93.1 (02-07-2025).
CVE-2025-48108Medium (6.5)0.23%—Aug 26, 2025
Missing Authorization vulnerability in Mojoomla School Management allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects School Management: from n/a through 93.2.0.
CVE-2025-47574High (7.1)0.25%—Jun 27, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mojoomla School Management allows Reflected XSS. This issue affects School Management: from n/a through 92.0.0.
CVE-2025-47573Critical (9.3)0.45%—Jun 17, 2025
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mojoomla School Management allows Blind SQL Injection. This issue affects School Management: from n/a through 92.0.0.
CVE-2025-47572High (7.5)0.72%—Jun 17, 2025
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in mojoomla School Management allows PHP Local File Inclusion. This issue affects School Management:…
CVE-2025-47613High (7.1)0.28%—May 23, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mojoomla School Management allows Reflected XSS. This issue affects School Management: from n/a through 92.0.0.
CVE-2025-47575High (8.5)0.33%—May 23, 2025
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mojoomla School Management allows SQL Injection. This issue affects School Management: from n/a through 92.0.0.

🎯 How it gets exploited (ATT&CK techniques)

  1. T1210 Exploitation of Remote Services5
  2. T1005 Data from Local System3
  3. T1059.007 JavaScript2
  4. T1189 Drive-by Compromise2
  5. T1059 Command and Scripting Interpreter1
  6. T1068 Exploitation for Privilege Escalation1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Mojoomla