CVE-2026-8208
Gibbon versions before v30.0.01 are affected by a local file inclusion vulnerability resulting in RCE by changing the report archive directory and forcing interpretation of a user provided .zip as PHP. Successful exploitation requires Teacher or higher privileges. Exploitation could result in compromise of the underlying web server.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.9
- CVSS vector
- CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
- EPSS probability
- 0.32%
- CWE
- CWE-98
- Published
- 2026-05-09
- Last modified
- 2026-05-11
Affected products
- gibbonedu gibbon
Weakness type
Related vulnerabilities
- CVE-2026-41228 — Froxlor has Local File Inclusion via path traversal in API `def_language` parameter that leads to Remote Code Execution
- CVE-2026-9559 — A path traversal vulnerability exists in the campaign import feature of Mautic 7. When extracting uploaded ZIP files dur
- CVE-2026-11613 — Divi Ajax Filter <= 5.1.2 - Unauthenticated Local File Inclusion via 'custom_loop_template' Parameter
- CVE-2026-7515 — BetterDocs Pro <= 3.8.0 - Unauthenticated Local File Inclusion via doc_style
- CVE-2026-66587 — WordPress WP Cafe Pro plugin < 3.0.15 - Local File Inclusion vulnerability
- CVE-2026-8134 — Concrete CMS 9.5.0 and below is vulnerable to Authenticated RCE via Composer customTemplate Path Traversal leading to PHP File Inclusion
- CVE-2026-44177 — Kirby: Pre-authentication path traversal and PHP file inclusion during user lookup
- CVE-2026-87927 — MaxSite CMS through 109.6 Local File Inclusion via ajax dispatcher