Stats Digest Feeds
โ† Back to all CVEs

CVE-2025-61872

UNKNOWN NVD
CVSS Score 0
Severity UNKNOWN
Published Apr 24, 2026
Vendor unknown

Description

Mahara before 25.04.2 and 24.04.11 are vulnerable to displaying results that can trigger XSS via a malicious search query string. This occurs in the 'search site' feature when using the Elasticsearch7 search plugin. The Elasticsearch function does not properly sanitize input in the query parameter.

References