CVE-2026-31281 PUBLISHED

Assigner: mitre
Reserved: 09.03.2026 Published: 13.04.2026 Updated: 13.04.2026

Totara LMS v19.1.5 and before is vulnerable to HTLM Injection. An attacker can inject malicious HTLM code in a message and send it to all the users in the application, resulting in executing the code and may lead to session hijacking and executing commands on the victim's browser.

Product Status

Vendor n/a
Product n/a
Versions
  • Version n/a is affected

References

Problem Types

  • n/a text