HIGH 8.7 GitHub

CVE-2026-54049

Sakai Conversations has a Stored XSS Issue

### Summary The Sakai Conversations tool stores topic and post messages without HTML sanitization, and the frontend renders them using LitElement's `unsafeHTML()` directive, resulting in stored cross-site scripting (XSS). Any authenticated user with access to a site that has the Conversations tool enabled can inject arbitrary HTML and JavaScript that executes in the browsers of all other users who view that topic or post. ### Description The Conversations REST API endpoint `POST /api/sites/{

Affected Products

References

Published: 2026-08-24 · Source: GitHub · Feed updated: 2026-08-24
This high severity vulnerability with a CVSS score of 8.7 was published on 2026-08-24 via GitHub. Affected: maven/org.sakaiproject.conversations:sakai-conversations-impl >= 23.0, <= 23.3, maven/org.sakaiproject.kernel:sakai-kernel-impl >= 23.0, <= 23.3, maven/org.sakaiproject.rubrics:rubrics-impl >= 23.0, <= 23.3.
vulnfeed aggregates 11313 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.