Apereo Xerte Online Toolkits
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Apereo Xerte Online Toolkits.
By the Year
In 2026 there have been 1 vulnerability in Apereo Xerte Online Toolkits with an average score of 9.8 out of ten.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 1 | 9.80 |
It may take a day or so for new Xerte Online Toolkits vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Apereo Xerte Online Toolkits Security Vulnerabilities
Xerte Online Toolkits 3.14- CRU: Unauthenticated File Upload in Import.php
CVE-2026-32985
9.8 - Critical
- March 20, 2026
Xerte Online Toolkits versions 3.14 and earlier contain an unauthenticated arbitrary file upload vulnerability in the template import functionality that allows remote attackers to execute arbitrary code by uploading a crafted ZIP archive containing malicious PHP payloads. Attackers can bypass authentication checks in the import.php file to upload a template archive with PHP code in the media directory, which gets extracted to a web-accessible path where the malicious PHP can be directly accessed and executed under the web server context.
Missing Authentication for Critical Function
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Apereo Xerte Online Toolkits or by Apereo? Click the Watch button to subscribe.