CVE-2020-15907: Mahara

Medium severity, CVSS 6.1. EPSS: 0.7% chance of exploitation in the next 30 days.

In Mahara 19.04 before 19.04.6, 19.10 before 19.10.4, and 20.04 before 20.04.1, certain places could execute file or folder names containing JavaScript.

Affected products

  • Mahara Mahara: from 19.04, before 19.04.6 (fixed in 19.04.6); from 19.10, before 19.10.4 (fixed in 19.10.4); from 20.04, before 20.04.1 (fixed in 20.04.1)

Published 2020-08-07. Last modified 2026-06-17.