Gibbon vulnerabilities
CVEs whose affected-version data names the Gibbon package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-97864Medium· 5.3PoCA vulnerability has been found in GibbonEdu Gibbon up to 30.0.01
A vulnerability has been found in GibbonEdu Gibbon up to 30.0.01. The affected element is the function makeBlock of the file modules/Planner/units_add_blockAjax.php of the component Unit Planner. The manipulation of the argument gibbonUn…
▾ TwilightGibbonEdu · Gibbonvia NVD
CVE-2022-27305High· 8.8Gibbon v23 does not generate a new session ID cookie after a user authenticates, making the application vulnerable to session fixation.
Gibbon v23 does not generate a new session ID cookie after a user authenticates, making the application vulnerable to session fixation.
▾ Twilightgibbonedu · gibbonEPSS 0.92%via NVD