Cross-site scripting in Sakai - CVE-2026-33402
Published: April 28, 2026
Sakai
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary script code in a victim's browser.
The vulnerability exists due to cross-site scripting in site-manage group titles and descriptions when rendering stored group content. A remote attacker can inject a crafted script into a group title or description to execute arbitrary script code in a victim's browser.