Gibbonedu maintains Gibbon, a focused open-source school management and student information platform whose modest product scope masks significant prominence in educational deployments. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a strong tendency toward public exploit availability, while the recurring weakness classes—cross-site scripting, path traversal, CSRF, untrusted deserialization, and template-injection flaws—reflect the web-application and data-handling attack surface typical of administrative platforms. Defenders managing educational infrastructure should prioritize this vendor's security updates and treat exposed instances as high-value targets for both compromise and lateral movement. Current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gibbonedu over time
Signals from CVEs in this vendor scope (19 CVEs).
19 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-45878CRITICAL GibbonEdu Gibbon version 25.0.1 and before allows Arbitrary File Write because rubrics_visualise_saveAjax.phps does not require authentication. The endpoint accepts the img, path, | Nov 14, 2023 | 9.8 | 75 | NO | YES |
CVE-2023-34598CRITICAL Gibbon v25.0.0 is vulnerable to a Local File Inclusion (LFI) where it's possible to include the content of several files present in the installation folder in the server's response | Jun 29, 2023 | 9.8 | 68 | NO | YES |
CVE-2024-24725HIGH Gibbon through 26.0.00 allows remote authenticated users to conduct PHP deserialization attacks via columnOrder in a POST request to the modules/System%20Admin/import_run.php&type= | Mar 23, 2024 | 8.8 | 63 | NO | YES |
CVE-2024-24724CRITICAL Gibbon through 26.0.00 allows /modules/School%20Admin/messengerSettings.php Server Side Template Injection leading to Remote Code Execution because input is passed to the Twig temp | Apr 3, 2024 | 9.8 | 51 | NO | YES |
CVE-2026-8208HIGH Gibbon versions before v30.0.01 are affected by a local file inclusion vulnerability resulting in RCE by changing the report archive directory and forcing interpretation of a user | May 9, 2026 | 8.9 | 33 | NO | NO |
CVE-2023-34599MEDIUM Multiple Cross-Site Scripting (XSS) vulnerabilities have been identified in Gibbon v25.0.0, which enable attackers to execute arbitrary Javascript code. | Jun 29, 2023 | 6.1 | 29 | NO | YES |
CVE-2022-27305HIGH Gibbon v23 does not generate a new session ID cookie after a user authenticates, making the application vulnerable to session fixation. | May 25, 2022 | 8.8 | 29 | NO | NO |
CVE-2026-8209MEDIUM Gibbon versions before v30.0.01 are affected by a path traversal vulnerability resulting in DOS by attempting extraction of web application PHP files, failed .zip extraction result | May 9, 2026 | 6.9 | 28 | NO | NO |
CVE-2026-8207HIGH Gibbon versions before v30.0.01 are affected by an authenticated SQL Injection vulnerability by abusing the Tracking/graphing https://github.com/GibbonEdu/core/blob/c431e25fdc874a | May 9, 2026 | 7.0 | 28 | NO | NO |
CVE-2025-26211HIGH Gibbon before 29.0.00 allows CSRF. | May 27, 2025 | 8.8 | 23 | NO | NO |
Signals from CVEs in this vendor scope (19 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gibbonedu.
Media articles that mention a CVE ID that affects a product developed by Gibbonedu — matched by CVE ID, not by vendor name.