Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 31 Mar 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sakailms
Sakailms sakai |
|
| CPEs | cpe:2.3:a:sakailms:sakai:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Sakailms
Sakailms sakai |
|
| Metrics |
cvssV3_1
|
Fri, 27 Mar 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sakaiproject
Sakaiproject sakai |
|
| Vendors & Products |
Sakaiproject
Sakaiproject sakai |
Thu, 26 Mar 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 26 Mar 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Sakai is a Collaboration and Learning Environment (CLE). In versions 23.0 through 23.4 and 25.0 through 25.1, group titles and description can contain cross-site scripting scripts. The patch is included in releases 25.2 and 23.5. As a workaround, one can check the SAKAI_SITE_GROUP table for titles and descriptions that contain this info. | |
| Title | SAK-52311: Sakai site-manage group titles can contain XSS content | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-26T18:49:31.777Z
Reserved: 2026-03-19T17:02:34.170Z
Link: CVE-2026-33402
Updated: 2026-03-26T18:49:28.510Z
Status : Analyzed
Published: 2026-03-26T17:16:38.287
Modified: 2026-03-31T13:11:41.240
Link: CVE-2026-33402
No data.
OpenCVE Enrichment
Updated: 2026-03-31T20:08:45Z