Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Gibbonedu

First CVE: Sep 3, 2021Active for: 5 yearsTotal CVEs: 19
53.7
VTI Score
TOP TARGET

Gibbonedu maintains Gibbon, a focused open-source school management and student information platform whose modest product scope masks significant prominence in educational deployments. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a strong tendency toward public exploit availability, while the recurring weakness classes—cross-site scripting, path traversal, CSRF, untrusted deserialization, and template-injection flaws—reflect the web-application and data-handling attack surface typical of administrative platforms. Defenders managing educational infrastructure should prioritize this vendor's security updates and treat exposed instances as high-value targets for both compromise and lateral movement. Current exploitation activity and severity counts are shown alongside this summary.

FAUCET AI Generated
19
Total CVEs
More Total CVEs than 96% of tracked vendors
3.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 94% of tracked vendors
7.1
Avg CVSS Score
Higher Avg CVSS Score than 51% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Gibbonedu over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 3, 2021
4 years ago
Most Recent CVE
May 9, 2026
76 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (19 CVEs).

19 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-45878CRITICAL
GibbonEdu Gibbon version 25.0.1 and before allows Arbitrary File Write because rubrics_visualise_saveAjax.phps does not require authentication. The endpoint accepts the img, path,
Nov 14, 20239.875NOYES
CVE-2023-34598CRITICAL
Gibbon v25.0.0 is vulnerable to a Local File Inclusion (LFI) where it's possible to include the content of several files present in the installation folder in the server's response
Jun 29, 20239.868NOYES
CVE-2024-24725HIGH
Gibbon through 26.0.00 allows remote authenticated users to conduct PHP deserialization attacks via columnOrder in a POST request to the modules/System%20Admin/import_run.php&type=
Mar 23, 20248.863NOYES
CVE-2024-24724CRITICAL
Gibbon through 26.0.00 allows /modules/School%20Admin/messengerSettings.php Server Side Template Injection leading to Remote Code Execution because input is passed to the Twig temp
Apr 3, 20249.851NOYES
CVE-2026-8208HIGH
Gibbon versions before v30.0.01 are affected by a local file inclusion vulnerability resulting in RCE by changing the report archive directory and forcing interpretation of a user
May 9, 20268.933NONO
CVE-2023-34599MEDIUM
Multiple Cross-Site Scripting (XSS) vulnerabilities have been identified in Gibbon v25.0.0, which enable attackers to execute arbitrary Javascript code.
Jun 29, 20236.129NOYES
CVE-2022-27305HIGH
Gibbon v23 does not generate a new session ID cookie after a user authenticates, making the application vulnerable to session fixation.
May 25, 20228.829NONO
CVE-2026-8209MEDIUM
Gibbon versions before v30.0.01 are affected by a path traversal vulnerability resulting in DOS by attempting extraction of web application PHP files, failed .zip extraction result
May 9, 20266.928NONO
CVE-2026-8207HIGH
Gibbon versions before v30.0.01 are affected by an authenticated SQL Injection vulnerability by abusing the Tracking/graphing https://github.com/GibbonEdu/core/blob/c431e25fdc874a
May 9, 20267.028NONO
CVE-2025-26211HIGH
Gibbon before 29.0.00 allows CSRF.
May 27, 20258.823NONO
View all 19 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products19 CVEs
47%
32%
16%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network19 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low17 (89.5%)
High2 (10.5%)
Unknown0 (0.0%)
User Interaction
None8 (42.1%)
Unknown0 (0.0%)
Required11 (57.9%)
Privileges Required
Low5 (26.3%)
High5 (26.3%)
None9 (47.4%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (19 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
5.3% of CVEs· 98th percentile
Nuclei
3 CVEs
15.8% of CVEs· 97th percentile
ExploitDB
1 CVE
5.3% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Gibbonedu.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Gibbonedu — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Gibbonedu's Products

View all 2 CNAs →

Top CWEs