Products

Showing 8 vulnerabilities on this page

Signals CISA KEV Ransomware Nuclei
gibbonedu vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Generated title:Gibbon Path Traversal Denial of Service

Gibbon versions before v30.0.01 are affected by a path traversal vulnerability resulting in DOS by attempting extraction of web application PHP files, failed .zip extraction results in deletion of the file and a DOS condition. Successful exploitation requires Teacher or higher privileges. Exploitation could result in loss of availability of the web application.

CWE-23May 9, 2026
CVSS6.9v4.0EPSS0.293%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:Gibbon Local File Inclusion Vulnerability Leading to Remote Code Execution

Gibbon versions before v30.0.01 are affected by a local file inclusion vulnerability resulting in RCE by changing the report archive directory and forcing interpretation of a user provided .zip as PHP. Successful exploitation requires Teacher or higher privileges. Exploitation could result in compromise of the underlying web server.

CWE-98May 9, 2026
CVSS8.9v4.0EPSS0.32%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:Gibbon Tracking Module SQL Injection

Gibbon versions before v30.0.01 are affected by an authenticated SQL Injection vulnerability by abusing the Tracking/graphing https://github.com/GibbonEdu/core/blob/c431e25fdc874adece5d2dc7e408e9aa2d1abadb/modules/Tracking/graphing.php#L145 feature. Successful exploitation requires Teacher or higher privileges. Exploitation could result in unintended read/write activities to the underlying database.

CWE-89May 9, 2026
CVSS7.0v4.0EPSS0.226%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Gibbon before 29.0.00 allows CSRF.

CWE-352May 27, 2025
CVSS3.7v3.1EPSS0.164%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Gibbon LMS v26.0.00 - SSTI vulnerability

Gibbon through 26.0.00 allows /modules/School%20Admin/messengerSettings.php Server Side Template Injection leading to Remote Code Execution because input is passed to the Twig template engine (messengerSettings.php) without sanitization.

CWE-1336Apr 3, 2024
CVSS9.8v3.1EPSS26.1%PoCs1SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Gibbon LMS < v26.0.00 - Authenticated RCE

Gibbon through 26.0.00 allows remote authenticated users to conduct PHP deserialization attacks via columnOrder in a POST request to the modules/System%20Admin/import_run.php&type=externalAssessment&step=4 URI.

CWE-502Mar 23, 2024
CVSS8.8v3.1EPSS51.3%PoCs3SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

GibbonEdu Gibbon 'img parameter' Unauthenticated Remote Code Execution

GibbonEdu Gibbon version 25.0.1 and before allows Arbitrary File Write because rubrics_visualise_saveAjax.phps does not require authentication. The endpoint accepts the img, path, and gibbonPersonID parameters. The img parameter is expected to be a base64 encoded image. If the path parameter is set, the defined path is used as the destination folder, concatenated with the absolute path of the installation directory. The content of the img parameter is base64 decoded and written to the defined fi

CWE-787Nov 14, 20231 related artifact
CVSS9.8v3.1EPSS63.1%PoCs7SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

gibbonedu gibbon Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Gibbon v25.0.0 is vulnerable to a Local File Inclusion (LFI) where it's possible to include the content of several files present in the installation folder in the server's response.

CWE-22Jun 29, 20231 related artifact
CVSS9.8v3.1EPSS47.2%PoCs3SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX