Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Mahara

First CVE: Jan 22, 2008Active for: 19 yearsTotal CVEs: 109
31.5
VTI Score
Medium

Mahara is an open-source learning and portfolio platform widely deployed in educational institutions, where its disclosures span a moderate but concentrated vulnerability profile across the core application and mobile variants. Its vulnerability exposure clusters around web application and session-management weaknesses, recurringly including cross-site scripting, improper input neutralization, exposure of sensitive information, cross-site request forgery, and insufficient session expiration—issues characteristic of web applications that handle user-generated content and authentication state. The platform's educational deployment context and reliance on user data create a durable attack surface centered on confidentiality and integrity rather than remote code execution. Defenders should prioritize input-validation and session-management practices when securing Mahara instances and treat the platform's advisories as relevant to their educational infrastructure. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
109
Total CVEs
More Total CVEs than 99% of tracked vendors
4.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 97% of tracked vendors
6.1
Avg CVSS Score
Higher Avg CVSS Score than 30% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Mahara over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 22, 2008
18 years ago
Most Recent CVE
Aug 26, 2025
332 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (109 CVEs).

109 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-45134CRITICAL
Mahara 21.10 before 21.10.6, 22.04 before 22.04.4, and 22.10 before 22.10.1 deserializes user input unsafely during skin import. A particularly structured XML file could cause code
Aug 22, 20259.834NONO
CVE-2022-44544CRITICAL
Mahara 21.04 before 21.04.7, 21.10 before 21.10.5, 22.04 before 22.04.3, and 22.10 before 22.10.0 potentially allow a PDF export to trigger a remote shell if the site is running on
Nov 6, 20229.832NONO
CVE-2012-2237MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in Mahara 1.4.x before 1.4.3 and 1.5.x before 1.5.2 allow remote attackers to inject arbitrary web script or HTML via vectors re
Dec 17, 20196.132NOYES
CVE-2017-1000171CRITICAL
Mahara Mobile before 1.2.1 is vulnerable to passwords being sent to the Mahara access log in plain text.
Nov 3, 20179.830NONO
CVE-2012-2239CRITICAL
Mahara 1.4.x before 1.4.4 and 1.5.x before 1.5.3 allows remote attackers to read arbitrary files or create TCP connections via an XML external entity (XXE) injection attack, as dem
Nov 24, 20129.130NONO
CVE-2021-40849CRITICAL
In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, the account associated with a web services token is vulnerable to being exploited and logged into, resulting in information
Nov 3, 20219.829NONO
CVE-2017-1000153CRITICAL
Mahara 15.04 before 15.04.10 and 15.10 before 15.10.6 and 16.04 before 16.04.4 are vulnerable to incorrect access control after the password reset link is sent via email and then u
Nov 3, 20179.829NONO
CVE-2017-1000152CRITICAL
Mahara 15.04 before 15.04.7 and 15.10 before 15.10.3 running PHP 5.3 are vulnerable to one user being logged in as another user on a separate computer as the same session ID is ser
Nov 3, 20179.829NONO
CVE-2024-39335CRITICAL
Supported versions of Mahara 24.04 before 24.04.1 and 23.04 before 23.04.6 are vulnerable to information being disclosed to an institution administrator under certain conditions vi
Aug 26, 20259.128NONO
CVE-2024-47853HIGH
An issue was discovered in Mahara 23.04.8 and 24.04.4. Attackers may utilize escalation of privileges in certain cases when logging into Mahara with Learning Tools Interoperability
Aug 26, 20258.827NONO
View all 109 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products109 CVEs
72%
18%
8%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local3 (2.8%)
Network67 (61.5%)
Unknown38 (34.9%)
Physical1 (0.9%)
Adjacent Network0 (0.0%)
Attack Complexity
Low69 (63.3%)
High2 (1.8%)
Unknown38 (34.9%)
User Interaction
None43 (39.4%)
Unknown38 (34.9%)
Required28 (25.7%)
Privileges Required
Low28 (25.7%)
High7 (6.4%)
None36 (33.0%)
Unknown38 (34.9%)

Exploit Exposure

Signals from CVEs in this vendor scope (109 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
0.9% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Mahara.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Mahara — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Mahara's Products

View all 3 CNAs →

Top CWEs