CVE-2026-108113
- EPSS -
- Veröffentlicht 09.10.2026 15:04:59
- Zuletzt bearbeitet 09.10.2026 16:17:27
ILIAS before 9.24, 10.12, and 11.5 contains an unrestricted file upload vulnerability in QTI question import image handling (ilQtiMatImageSecurity) that allows authenticated authors to write executable files. Attackers with question pool import right...
CVE-2026-107639
- EPSS 0.68%
- Veröffentlicht 08.10.2026 14:10:35
- Zuletzt bearbeitet 08.10.2026 15:17:47
ILIAS before 9.24, 10.x before 10.12 and 11.x before 11.5 contains an argument injection vulnerability in assImagemapQuestionGUI that allows question authors to inject ImageMagick convert options via uploaded image filenames. Attackers can embed tab-...
CVE-2023-32778
- EPSS 0.22%
- Veröffentlicht 14.09.2026 00:00:00
- Zuletzt bearbeitet 22.09.2026 20:00:03
An issue was discovered in ILIAS 6.23, 7 before 7.22, and 8.1. An attacker can execute arbitrary code via ZIP upload.
CVE-2026-86416
- EPSS 0.25%
- Veröffentlicht 07.09.2026 12:23:54
- Zuletzt bearbeitet 18.09.2026 18:17:18
ILIAS versions before 9.23, 10.11, and 11.4 contain an authorization bypass vulnerability in ilObjGroupGUI where saveMapSettingsObject() and updateGroupTypeObject() perform state-changing operations without write permission checks. Authenticated user...
CVE-2026-82538
- EPSS 0.39%
- Veröffentlicht 04.09.2026 17:37:16
- Zuletzt bearbeitet 30.09.2026 17:16:50
ILIAS before versions 9.22, 10.10, and 11.3 contains a SQL injection vulnerability in the repository trash table where the table navigation sort field from HTTP requests is passed directly into the ORDER BY clause of a SQL query without validation ag...
CVE-2026-85135
- EPSS 0.21%
- Veröffentlicht 03.09.2026 14:00:08
- Zuletzt bearbeitet 03.09.2026 17:25:25
A security flaw has been discovered in ILIAS up to 9.21/10.9/11.2. This affects the function ilObjMediaObjectGUI::uploadMultipleSubtitleFileObject of the file Services/Repository/Service/Resources/ZipAdapter.php of the component MediaPool. The manipu...
CVE-2026-82877
- EPSS 0.33%
- Veröffentlicht 31.08.2026 10:51:03
- Zuletzt bearbeitet 30.09.2026 17:16:50
ILIAS before versions 9.22, 10.10, and 11.3 contains an arbitrary file read vulnerability in the SOAP addFile method that allows authenticated users to read server files by supplying crafted XML with COPY-mode imports. Attackers can construct absolut...
CVE-2020-36944
- EPSS 0.19%
- Veröffentlicht 28.01.2026 17:35:07
- Zuletzt bearbeitet 09.02.2026 18:13:36
ILIAS Learning Management System 4.3 contains a server-side request forgery vulnerability that allows attackers to read local files through portfolio PDF export functionality. Attackers can inject a script that uses XMLHttpRequest to retrieve local f...
CVE-2025-11346
- EPSS 0.41%
- Veröffentlicht 06.10.2025 19:32:05
- Zuletzt bearbeitet 23.01.2026 19:15:52
A vulnerability has been found in ILIAS up to 8.23/9.13/10.1. This affects the function unserialize of the component Base64 Decoding Handler. Such manipulation of the argument f_settings leads to deserialization. It is possible to launch the attack r...
CVE-2025-11345
- EPSS 0.33%
- Veröffentlicht 06.10.2025 19:15:34
- Zuletzt bearbeitet 23.01.2026 19:15:52
A flaw has been found in ILIAS up to 8.23/9.13/10.1. Affected by this issue is the function unserialize of the component Test Import. This manipulation causes deserialization. It is possible to initiate the attack remotely. Upgrading to version 8.24,...