CVE-2025-10584Low· 3.5▾ SunlitA vulnerability was identified in Portabilis i-Educar up to 2.10. Impacted is an unknown function of the file /intranet/educar_calendario_anotacao_cad.php. Such manipulation of the argument nm_anotacao/descricao leads to cross site scrip…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 19.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
A vulnerability was identified in Portabilis i-Educar up to 2.10. Impacted is an unknown function of the file /intranet/educar_calendario_anotacao_cad.php. Such manipulation of the argument nm_anotacao/descricao leads to cross site scripting. It is possible to launch the attack remotely. The exploit is publicly available and might be used.
i-educar <= 2.10.0Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-10605Medium· 4.3A security flaw has been discovered in Portabilis i-Educar up to 2.10
CVE-2025-10590Medium· 4.3A security flaw has been discovered in Portabilis i-Educar up to 2.10
CVE-2025-10591Low· 3.5A weakness has been identified in Portabilis i-Educar up to 2.10
CVE-2025-8538Low· 2.4A security flaw has been discovered in Portabilis i-Educar 2.10
CVE-2025-8539Low· 2.4A weakness has been identified in Portabilis i-Educar 2.10
CVE-2023-5578Low· 3.5A vulnerability was detected in Portábilis i-Educar up to 2.7.5