Vulnerabilities

Summary — last 7 days

New vulnerabilities2,568▼ 306 vs. last week
Critical / high1,351▲ 96 vs. last week
New active exploitation (KEV)5▼ 7 vs. last week
Unscored (no CVSS)62▼ 466 vs. last week
–

6 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
DeferredHigh (8.7)0.26%—Sakailms SakaiAI10/1/202610/2/2026
Sakai is a Collaboration and Learning Environment (CLE). From versions 23.0 to before 23.5, and versions 25.0 to before 25.3, the Sakai Conversations tool stores topic and post messages without HTML sanitization, and the frontend renders them using LitElement's unsafeHTML() directive, resulting in stored cross-site…
Awaiting AnalysisMedium (6.5)0.31%—Sakailms SakaiAI9/15/20269/25/2026
Sakai is a Collaboration and Learning Environment (CLE). From 23.0 until 23.5 and 25.3, the DELETE /api/users/{userId}/profile/image endpoint allows an authenticated user to delete another user's profile image because ProfileController.removeProfileImage() passes the attacker-controlled userId to…
AnalyzedLow (1.3)0.26%—Sakailms Sakai3/26/20266/17/2026
Sakai is a Collaboration and Learning Environment (CLE). In versions 23.0 through 23.4 and 25.0 through 25.1, group titles and description can contain cross-site scripting scripts. The patch is included in releases 25.2 and 23.5. As a workaround, one can check the SAKAI_SITE_GROUP table for titles and descriptions…
AnalyzedMedium (5.9)0.20%—Sakailms Sakai10/22/20256/17/2026
Sakai is a Collaboration and Learning Environment. Prior to versions 23.5 and 25.0, EncryptionUtilityServiceImpl initialized an AES256TextEncryptor password (serverSecretKey) using RandomStringUtils with the default java.util.Random. java.util.Random is a non‑cryptographic PRNG and can be predicted from limited…
AnalyzedHigh (8.7)0.57%—Sakailms Sakai10/15/20246/17/2026
Sakai is a Collaboration and Learning Environment. Starting in version 23.0 and prior to version 23.2, kernel users created with type roleview can log in as a normal user. This can result in illegal access being granted to the system. Version 23.3 fixes this vulnerability.
ModifiedMedium (6.1)0.83%—Sakailms Sakai9/9/20196/17/2026
Sakai through 12.6 allows XSS via a chat user name.