Xerte Online Toolkits Apereo Xerte Online Toolkits

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Apereo Xerte Online Toolkits.

By the Year

In 2026 there have been 1 vulnerability in Apereo Xerte Online Toolkits with an average score of 9.8 out of ten.

Year Vulnerabilities Average Score
2026 1 9.80

It may take a day or so for new Xerte Online Toolkits vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Apereo Xerte Online Toolkits Security Vulnerabilities

Xerte Online Toolkits 3.14- CRU: Unauthenticated File Upload in Import.php
CVE-2026-32985 9.8 - Critical - March 20, 2026

Xerte Online Toolkits versions 3.14 and earlier contain an unauthenticated arbitrary file upload vulnerability in the template import functionality that allows remote attackers to execute arbitrary code by uploading a crafted ZIP archive containing malicious PHP payloads. Attackers can bypass authentication checks in the import.php file to upload a template archive with PHP code in the media directory, which gets extracted to a web-accessible path where the malicious PHP can be directly accessed and executed under the web server context.

Missing Authentication for Critical Function

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Apereo Xerte Online Toolkits or by Apereo? Click the Watch button to subscribe.

Apereo
Vendor

subscribe