Security-Blog
April 2026
Following 2 security issues have been resolved:
0047313: News: Unauthorized Access to News Settings
0047428: Text Subset Question: Stored XSS
Following 2 security issues have been resolved:
0047313: News: Unauthorized Access to News Settings
0047428: Text Subset Question: Stored XSS
March 2026
Following 3 security issues have been resolved:
0046459: SAML: Open redirect on logout
0046641: Survey: Stored XSS with TinyMCE
0046937: Auth: Logout via CSRF / Potential DoS (Regression)
Following 2 security issues have been resolved:
0046459: SAML: Open redirect on logout
0046641: Survey: Stored XSS with TinyMCE
January 2026
Following 2 security issues have been resolved:
0046643: Exercise: Stored XSS with TinyMCE
0046763: Chatroom: Potential DoS via memory exhaustion (CVE-2025-15284)