« Back to list

Sakailms

Sakailms Sakai: vulnerabilities and CVEs

Sakailms Sakai has 6 published vulnerabilities, 4 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.

CVEs6
Last 12 months4
Critical0
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-54049High (8.7)0.26%—Oct 1, 2026
Sakai is a Collaboration and Learning Environment (CLE). From versions 23.0 to before 23.5, and versions 25.0 to before 25.3, the Sakai Conversations tool stores topic and post messages without HTML sanitization, and…
CVE-2026-54050Medium (6.5)0.31%—Sep 15, 2026
Sakai is a Collaboration and Learning Environment (CLE). From 23.0 until 23.5 and 25.3, the DELETE /api/users/{userId}/profile/image endpoint allows an authenticated user to delete another user's profile image because…
CVE-2026-33402Low (1.3)0.26%—Mar 26, 2026
Sakai is a Collaboration and Learning Environment (CLE). In versions 23.0 through 23.4 and 25.0 through 25.1, group titles and description can contain cross-site scripting scripts. The patch is included in releases 25.2…
CVE-2025-62710Medium (5.9)0.20%—Oct 22, 2025
Sakai is a Collaboration and Learning Environment. Prior to versions 23.5 and 25.0, EncryptionUtilityServiceImpl initialized an AES256TextEncryptor password (serverSecretKey) using RandomStringUtils with the default…
CVE-2024-47876High (8.7)0.57%—Oct 15, 2024
Sakai is a Collaboration and Learning Environment. Starting in version 23.0 and prior to version 23.2, kernel users created with type roleview can log in as a normal user. This can result in illegal access being granted…
CVE-2019-16148Medium (6.1)0.83%—Sep 9, 2019
Sakai through 12.6 allows XSS via a chat user name.

🎯 How it gets exploited (ATT&CK techniques)

  1. T1059.007 JavaScript1
  2. T1078 Valid Accounts1
  3. T1189 Drive-by Compromise1
  4. T1190 Exploit Public-Facing Application1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.