ZeroHour

Vulnerabilities

4 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-33402
Sakai is a Collaboration and Learning Environment (CLE).

Sakai is a Collaboration and Learning Environment (CLE). In versions 23.0 through 23.4 and 25.0 through 25.1, group titles and description can contain cross-site scripting scripts. The patch is included in releases 25.2 and 23.5. As a workaround, one can check the SAKAI_SITE_GROUP table for titles and descriptions that contain this info.

NVD description · AI analysis pending
1.3<1%
  • sakailms sakai
CVE-2025-62710
Sakai is a Collaboration and Learning Environment.

Sakai is a Collaboration and Learning Environment. Prior to versions 23.5 and 25.0, EncryptionUtilityServiceImpl initialized an AES256TextEncryptor password (serverSecretKey) using RandomStringUtils with the default java.util.Random. java.util.Random is a non‑cryptographic PRNG and can be predicted from limited state/seed information (e.g., start time window), substantially reducing the effective search space of the generated key. An attacker who can obtain ciphertexts (e.g., exported or at‑rest strings protected by this service) and approximate the PRNG seed can feasibly reconstruct the serverSecretKey and decrypt affected data. SAK-49866 is patched in Sakai 23.5, 25.0, and trunk.

NVD description · AI analysis pending
5.9<1%
  • sakailms sakai
CVE-2024-47876
Sakai is a Collaboration and Learning Environment.

Sakai is a Collaboration and Learning Environment. Starting in version 23.0 and prior to version 23.2, kernel users created with type roleview can log in as a normal user. This can result in illegal access being granted to the system. Version 23.3 fixes this vulnerability.

NVD description · AI analysis pending
8.7<1%
  • sakailms sakai
CVE-2019-16148
Sakai through 12.6 allows XSS via a chat user name.

Sakai through 12.6 allows XSS via a chat user name.

NVD description · AI analysis pending
6.1<1%
  • sakailms sakai