CVE-2025-61872: XSS
Published Apr 24, 2026
·Updated
Mahara before 25.04.2 and 24.04.11 are vulnerable to displaying results that can trigger XSS via a malicious search query string. This occurs in the 'search site' feature when using the Elasticsearch7 search plugin. The Elasticsearch function does not properly sanitize input in the query parameter.
Affected Software
1 affected component
Mahara Mahara<25.04.2, <24.04.11
Event History
Apr 24, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-61872?
CVE-2025-61872 has a medium severity rating of 6.1.
2
How do I fix CVE-2025-61872?
To fix CVE-2025-61872, upgrade to Mahara version 25.04.2 or 24.04.11 or later.
3
What systems are affected by CVE-2025-61872?
CVE-2025-61872 affects Mahara versions prior to 25.04.2 and 24.04.11.
4
What type of vulnerability is CVE-2025-61872?
CVE-2025-61872 is an XSS (Cross-Site Scripting) vulnerability.
5
What functionality in Mahara is impacted by CVE-2025-61872?
CVE-2025-61872 affects the 'search site' feature when using the Elasticsearch7 search plugin.