{"id":"CVE-2026-33402","summary":"SAK-52311: Sakai site-manage group titles can contain XSS content","details":"Sakai is a Collaboration and Learning Environment (CLE). In versions 23.0 through 23.4 and 25.0 through 25.1, group titles and description can contain cross-site scripting scripts. The patch is included in releases 25.2 and 23.5. As a workaround, one can check the SAKAI_SITE_GROUP table for titles and descriptions that contain this info.","aliases":["GHSA-6g62-3898-hpvm"],"modified":"2026-07-15T01:49:04.135666380Z","published":"2026-03-26T16:45:59.734Z","database_specific":{"cwe_ids":["CWE-79"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/33xxx/CVE-2026-33402.json","cna_assigner":"GitHub_M"},"references":[{"type":"WEB","url":"https://sakaiproject.atlassian.net/browse/SAK-52311"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/33xxx/CVE-2026-33402.json"},{"type":"ADVISORY","url":"https://github.com/sakaiproject/sakai/security/advisories/GHSA-6g62-3898-hpvm"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-33402"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/sakaiproject/sakai","events":[{"introduced":"5d29a6077bcf22c8a9d2860fd655d7caecf3ab43"},{"fixed":"1947ba90029ebc72f1a9ad98ce9832cb8733fb48"},{"introduced":"4e5584bd462efb886ee35704724704460b2f4508"},{"fixed":"b5b7800f0fcddf9d0db47276a66065189365d905"}],"database_specific":{"extracted_events":[{"introduced":"23.0"},{"fixed":"23.5"},{"introduced":"25.0"},{"fixed":"25.2"}],"source":"CPE_RANGE","cpe":"cpe:2.3:a:sakailms:sakai:*:*:*:*:*:*:*:*"}}],"versions":["25.1","23.4","25.0","23.3","23.2","23.1","23.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-33402.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U"}]}