VendorsMarkUsProjectmarkusall versions
Vulnerabilities

MarkUsProject Markus

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

8CVEs
CVE-2026-25057
Zip Slip in MarkUs config upload allowing RCE
Published 2026-02-09 · Analyzed
9.1EPSS 0.005
CVE-2024-51743
Arbitrary File Write leading up to remote code execution (instructor accounts)
Published 2024-11-18 · Analyzed
8.8EPSS 0.007
CVE-2024-51499
MarkUs Arbitrary File Write leading up to remote code execution (student accounts)
Published 2024-11-18 · Analyzed
8.8EPSS 0.007
CVE-2026-28405
MarkUs: Stored XSS in Submission HTML Preview Enables Instructor-Context Actions
Published 2026-03-05 · Analyzed
8.0EPSS 0.004
CVE-2026-25962
MarkUs: Zip bomb in config upload enables DoS
Published 2026-03-06 · Analyzed
6.5EPSS 0.004
CVE-2026-24900
MarkUs has a submission-view IDOR exposes all student submissions
Published 2026-02-09 · Analyzed
6.5EPSS 0.003
CVE-2024-47820
MarkUs vulnerable to Path Traversal
Published 2024-11-18 · Analyzed
5.7EPSS 0.007
CVE-2026-27807
MarkUs: YAML alias (‘billion laughs’) DoS in config upload
Published 2026-03-06 · Analyzed
4.9EPSS 0.005