Mahara is an open-source learning and portfolio platform widely deployed in educational institutions, where its disclosures span a moderate but concentrated vulnerability profile across the core application and mobile variants. Its vulnerability exposure clusters around web application and session-management weaknesses, recurringly including cross-site scripting, improper input neutralization, exposure of sensitive information, cross-site request forgery, and insufficient session expiration—issues characteristic of web applications that handle user-generated content and authentication state. The platform's educational deployment context and reliance on user data create a durable attack surface centered on confidentiality and integrity rather than remote code execution. Defenders should prioritize input-validation and session-management practices when securing Mahara instances and treat the platform's advisories as relevant to their educational infrastructure. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mahara over time
Signals from CVEs in this vendor scope (109 CVEs).
109 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-45134CRITICAL Mahara 21.10 before 21.10.6, 22.04 before 22.04.4, and 22.10 before 22.10.1 deserializes user input unsafely during skin import. A particularly structured XML file could cause code | Aug 22, 2025 | 9.8 | 34 | NO | NO |
CVE-2022-44544CRITICAL Mahara 21.04 before 21.04.7, 21.10 before 21.10.5, 22.04 before 22.04.3, and 22.10 before 22.10.0 potentially allow a PDF export to trigger a remote shell if the site is running on | Nov 6, 2022 | 9.8 | 32 | NO | NO |
CVE-2012-2237MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Mahara 1.4.x before 1.4.3 and 1.5.x before 1.5.2 allow remote attackers to inject arbitrary web script or HTML via vectors re | Dec 17, 2019 | 6.1 | 32 | NO | YES |
CVE-2017-1000171CRITICAL Mahara Mobile before 1.2.1 is vulnerable to passwords being sent to the Mahara access log in plain text. | Nov 3, 2017 | 9.8 | 30 | NO | NO |
CVE-2012-2239CRITICAL Mahara 1.4.x before 1.4.4 and 1.5.x before 1.5.3 allows remote attackers to read arbitrary files or create TCP connections via an XML external entity (XXE) injection attack, as dem | Nov 24, 2012 | 9.1 | 30 | NO | NO |
CVE-2021-40849CRITICAL In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, the account associated with a web services token is vulnerable to being exploited and logged into, resulting in information | Nov 3, 2021 | 9.8 | 29 | NO | NO |
CVE-2017-1000153CRITICAL Mahara 15.04 before 15.04.10 and 15.10 before 15.10.6 and 16.04 before 16.04.4 are vulnerable to incorrect access control after the password reset link is sent via email and then u | Nov 3, 2017 | 9.8 | 29 | NO | NO |
CVE-2017-1000152CRITICAL Mahara 15.04 before 15.04.7 and 15.10 before 15.10.3 running PHP 5.3 are vulnerable to one user being logged in as another user on a separate computer as the same session ID is ser | Nov 3, 2017 | 9.8 | 29 | NO | NO |
CVE-2024-39335CRITICAL Supported versions of Mahara 24.04 before 24.04.1 and 23.04 before 23.04.6 are vulnerable to information being disclosed to an institution administrator under certain conditions vi | Aug 26, 2025 | 9.1 | 28 | NO | NO |
CVE-2024-47853HIGH An issue was discovered in Mahara 23.04.8 and 24.04.4. Attackers may utilize escalation of privileges in certain cases when logging into Mahara with Learning Tools Interoperability | Aug 26, 2025 | 8.8 | 27 | NO | NO |
Signals from CVEs in this vendor scope (109 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mahara.
Media articles that mention a CVE ID that affects a product developed by Mahara — matched by CVE ID, not by vendor name.