Portabilis
Portabilis I-educar: vulnerabilidades y CVE
Portabilis I-educar tiene 94 vulnerabilidades publicadas, 8 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE94
Últimos 12 meses8
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-4355 | Baja (2) | 0.33% | — | 18 mar 2026 | A vulnerability was detected in Portabilis i-Educar 2.11. This impacts an unknown function of the file /intranet/educar_servidor_curso_lst.php of the component Endpoint. Performing a manipulation of the argument Name… |
| CVE-2026-2064 | Baja (2) | 0.23% | — | 6 feb 2026 | A vulnerability was identified in Portabilis i-Educar up to 2.10. Affected by this vulnerability is an unknown functionality of the file /intranet/meusdadod.php of the component User Data Page. Such manipulation of the… |
| CVE-2026-2015 | Baja (2.1) | 0.31% | — | 6 feb 2026 | A weakness has been identified in Portabilis i-Educar up to 2.10. Affected is an unknown function of the file FinalStatusImportService.php of the component Final Status Import. Executing a manipulation of the argument… |
| CVE-2025-9638 | Media (4.8) | 0.21% | — | 9 dic 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Portabilis i-Educar allows Stored Cross-Site Scripting (XSS) via the matricula_interna parameter in the… |
| CVE-2025-65024 | Alta (7.2) | 0.40% | — | 19 nov 2025 | i-Educar is free, fully online school management software. In versions 2.10.0 and prior, an authenticated time-based SQL injection vulnerability exists in the ieducar/intranet/agenda_admin_cad.php script. An attacker… |
| CVE-2025-65023 | Alta (7.2) | 0.40% | — | 19 nov 2025 | i-Educar is free, fully online school management software. In versions 2.10.0 and prior, an authenticated time-based SQL injection vulnerability exists in the ieducar/intranet/funcionario_vinculo_cad.php script. An… |
| CVE-2025-65022 | Alta (7.2) | 0.31% | — | 19 nov 2025 | i-Educar is free, fully online school management software. In versions 2.10.0 and prior, an authenticated time-based SQL injection vulnerability exists in the ieducar/intranet/agenda.php script. An attacker with access… |
| CVE-2025-11554 | Baja (2.1) | 0.38% | — | 9 oct 2025 | A security vulnerability has been detected in Portabilis i-Educar up to 2.9.10. Affected by this issue is some unknown functionality of the file app/Http/Controllers/AccessLevelController.php of the component User Type… |
| CVE-2025-11050 | Baja (2.1) | 0.38% | — | 27 sept 2025 | A flaw has been found in Portabilis i-Educar up to 2.10. This affects an unknown part of the file /periodo-lancamento. Executing manipulation can lead to improper authorization. The attack can be executed remotely. The… |
| CVE-2025-11049 | Baja (2.1) | 0.38% | — | 27 sept 2025 | A vulnerability was detected in Portabilis i-Educar up to 2.10. Affected by this issue is some unknown functionality of the file /unificacao-aluno. Performing manipulation results in improper authorization. Remote… |
| CVE-2025-11048 | Baja (2.1) | 0.38% | — | 26 sept 2025 | A security vulnerability has been detected in Portabilis i-Educar up to 2.10. Affected by this vulnerability is an unknown functionality of the file /consulta-dispensas. Such manipulation leads to improper… |
| CVE-2025-11047 | Baja (2.1) | 0.38% | — | 26 sept 2025 | A weakness has been identified in Portabilis i-Educar up to 2.10. Affected is an unknown function of the file /module/Api/aluno. This manipulation of the argument aluno_id causes improper authorization. The attack may… |
| CVE-2025-10844 | Baja (2.1) | 0.43% | — | 23 sept 2025 | A vulnerability has been found in Portabilis i-Educar up to 2.10. Affected by this issue is some unknown functionality of the file /module/Cadastro/aluno. The manipulation of the argument is leads to sql injection.… |
| CVE-2025-10846 | Baja (2.1) | 0.43% | — | 23 sept 2025 | A vulnerability was determined in Portabilis i-Educar up to 2.10. This vulnerability affects unknown code of the file /module/ComponenteCurricular/edit. This manipulation of the argument ID causes sql injection. The… |
| CVE-2025-10845 | Baja (2.1) | 0.43% | — | 23 sept 2025 | A vulnerability was found in Portabilis i-Educar up to 2.10. This affects an unknown part of the file /module/ComponenteCurricular/view. The manipulation of the argument ID results in sql injection. The attack can be… |
| CVE-2025-10607 | Baja (2.1) | 0.40% | — | 17 sept 2025 | A security vulnerability has been detected in Portabilis i-Educar up to 2.10. Impacted is an unknown function of the file /module/Avaliacao/diarioApi. Such manipulation leads to information disclosure. The attack can be… |
| CVE-2025-10606 | Baja (2.1) | 0.40% | — | 17 sept 2025 | A weakness has been identified in Portabilis i-Educar up to 2.10. This issue affects some unknown processing of the file /module/Configuracao/ConfiguracaoMovimentoGeral. This manipulation of the argument tipoacao causes… |
| CVE-2025-10608 | Baja (2.1) | 0.38% | — | 17 sept 2025 | A vulnerability was detected in Portabilis i-Educar up to 2.10. The affected element is an unknown function of the file /enrollment-history/. Performing manipulation results in improper access controls. The attack is… |
| CVE-2025-10605 | Baja (2.1) | 0.40% | — | 17 sept 2025 | A security flaw has been discovered in Portabilis i-Educar up to 2.10. This vulnerability affects unknown code of the file /agenda_preferencias.php. The manipulation of the argument tipoacao results in cross site… |
| CVE-2025-10591 | Baja (2) | 0.24% | — | 17 sept 2025 | A weakness has been identified in Portabilis i-Educar up to 2.10. This affects an unknown function of the file /intranet/educar_funcao_cad.php of the component Editar Função Page. This manipulation of the argument… |
| CVE-2025-10590 | Baja (2.1) | 0.34% | — | 17 sept 2025 | A security flaw has been discovered in Portabilis i-Educar up to 2.10. The impacted element is an unknown function of the file /intranet/educar_usuario_det.php. The manipulation of the argument ref_pessoa results in… |
| CVE-2025-10584 | Baja (2) | 0.28% | — | 17 sept 2025 | A vulnerability was identified in Portabilis i-Educar up to 2.10. Impacted is an unknown function of the file /intranet/educar_calendario_anotacao_cad.php. Such manipulation of the argument nm_anotacao/descricao leads… |
| CVE-2025-10373 | Baja (2) | 0.24% | — | 13 sept 2025 | A security vulnerability has been detected in Portabilis i-Educar up to 2.10. The affected element is an unknown function of the file /intranet/educar_turma_tipo_cad.php. Such manipulation of the argument nm_tipo leads… |
| CVE-2025-10372 | Baja (2) | 0.24% | — | 13 sept 2025 | A weakness has been identified in Portabilis i-Educar up to 2.10. Impacted is an unknown function of the file /intranet/educar_modulo_cad.php. This manipulation of the argument nm_tipo/descricao causes cross site… |
| CVE-2025-10099 | Baja (1.9) | 0.29% | — | 8 sept 2025 | A weakness has been identified in Portabilis i-Educar up to 2.10. Affected by this vulnerability is an unknown functionality of the file /intranet/educar_usuario_cad.php of the component Editar usuário Page. This… |
| CVE-2025-10074 | Baja (2) | 0.29% | — | 8 sept 2025 | A vulnerability was identified in Portabilis i-Educar up to 2.10. The affected element is an unknown function of the file /usuarios/tipos/. The manipulation of the argument Tipos de Usuário/Descrição leads to cross site… |
| CVE-2025-10071 | Baja (2.1) | 0.33% | — | 7 sept 2025 | A vulnerability has been found in Portabilis i-Educar up to 2.10. This vulnerability affects unknown code of the file /cancelar-enturmacao-em-lote/. Such manipulation leads to improper access controls. The attack may be… |
| CVE-2025-10073 | Baja (2.1) | 0.36% | — | 7 sept 2025 | A vulnerability was determined in Portabilis i-Educar up to 2.10. Impacted is an unknown function of the file /module/Api/turma. Executing manipulation can lead to improper authorization. It is possible to launch the… |
| CVE-2025-10070 | Baja (2.1) | 0.33% | — | 7 sept 2025 | A flaw has been found in Portabilis i-Educar up to 2.10. This affects an unknown part of the file /enturmacao-em-lote/. This manipulation causes improper access controls. The attack is possible to be carried out… |
| CVE-2025-10072 | Baja (2.1) | 0.33% | — | 7 sept 2025 | A vulnerability was found in Portabilis i-Educar up to 2.10. This issue affects some unknown processing of the file /matricula/[ID_STUDENT]/enturmar/. Performing a manipulation results in improper access controls. It is… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.