CVE-2026-8207: SQL Injection
Gibbon versions before v30.0.01 are affected by an authenticated SQL Injection vulnerability by abusing the Tracking/graphing https://github.com/GibbonEdu/core/blob/c431e25fdc874adece5d2dc7e408e9aa2d1abadb/modules/Tracking/graphing.php#L145 feature. Successful exploitation requires Teacher or higher privileges. Exploitation could result in unintended read/write activities to the underlying database.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8207?
CVE-2026-8207 is classified as a high-severity authenticated SQL Injection vulnerability.
How do I fix CVE-2026-8207?
To mitigate CVE-2026-8207, update Gibbon to version 30.0.01 or later.
What versions of Gibbon are affected by CVE-2026-8207?
Gibbon versions prior to 30.0.01 are affected by CVE-2026-8207.
What type of vulnerability is CVE-2026-8207?
CVE-2026-8207 is an authenticated SQL Injection vulnerability.
What privileges are required to exploit CVE-2026-8207?
Exploitation of CVE-2026-8207 requires Teacher level access or higher.