📦 I Educar

by Portabilis

🔍 What is I Educar?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-65022

HIGH CVSS 7.2 Nov 19, 2025

An authenticated time-based SQL injection vulnerability in i-Educar school management software allows attackers with valid user credentials to execute arbitrary SQL commands against the database. This...

CVE-2025-65024

HIGH CVSS 7.2 Nov 19, 2025

An authenticated time-based SQL injection vulnerability in i-Educar school management software allows attackers with valid user sessions to execute arbitrary SQL commands against the database. This af...

CVE-2024-48325

HIGH CVSS 8.1 Nov 6, 2024

CVE-2024-48325 is an unauthenticated SQL injection vulnerability in Portabilis i-Educar 2.8.0 that allows remote attackers to execute arbitrary SQL commands. This affects all systems running the vulne...

CVE-2024-45058

HIGH CVSS 8.1 Aug 28, 2024

This vulnerability allows authenticated users with minimal viewing privileges in i-Educar school management software to escalate their privileges to Administrator level. Attackers can achieve this by ...

CVE-2025-9638

MEDIUM CVSS 4.8 Dec 9, 2025

This stored XSS vulnerability in Portabilis i-Educar allows attackers to inject malicious scripts via the matricula_interna parameter, which are then executed when other users view affected pages. It ...

CVE-2025-11554

MEDIUM CVSS 6.3 Oct 9, 2025

This vulnerability in Portabilis i-Educar allows attackers to escalate privileges through insecure inherited permissions in the User Type Handler component. Attackers can remotely exploit this to gain...

CVE-2025-11050

MEDIUM CVSS 6.3 Sep 27, 2025

CVE-2025-11050 is an improper authorization vulnerability in Portabilis i-Educar's /periodo-lancamento endpoint that allows remote attackers to bypass access controls. This affects i-Educar users up t...

CVE-2025-11049

MEDIUM CVSS 6.3 Sep 27, 2025

CVE-2025-11049 is an improper authorization vulnerability in Portabilis i-Educar's /unificacao-aluno endpoint that allows unauthorized access to student unification functionality. Attackers can exploi...

CVE-2025-11048

MEDIUM CVSS 6.3 Sep 26, 2025

This vulnerability allows attackers to bypass authorization controls in Portabilis i-Educar's /consulta-dispensas endpoint, potentially accessing unauthorized data or functions. It affects i-Educar ve...

CVE-2025-11047

MEDIUM CVSS 6.3 Sep 26, 2025

This vulnerability in Portabilis i-Educar allows attackers to bypass authorization controls and enumerate student records by manipulating the aluno_id parameter in the /module/Api/aluno endpoint. It a...

CVE-2025-10844

MEDIUM CVSS 6.3 Sep 23, 2025

This SQL injection vulnerability in Portabilis i-Educar allows attackers to execute arbitrary SQL commands through the /module/Cadastro/aluno endpoint. It affects i-Educar versions up to 2.10, potenti...

CVE-2025-10845

MEDIUM CVSS 6.3 Sep 23, 2025

This SQL injection vulnerability in Portabilis i-Educar allows attackers to execute arbitrary SQL commands by manipulating the ID parameter in the /module/ComponenteCurricular/view endpoint. This coul...

CVE-2025-10846

MEDIUM CVSS 6.3 Sep 23, 2025

This SQL injection vulnerability in Portabilis i-Educar allows attackers to manipulate database queries through the /module/ComponenteCurricular/edit endpoint. Attackers can potentially read, modify, ...

CVE-2025-10608

MEDIUM CVSS 6.3 Sep 17, 2025

This vulnerability in Portabilis i-Educar allows attackers to bypass access controls on the /enrollment-history/ endpoint, potentially accessing unauthorized student enrollment data. The vulnerability...

CVE-2025-10605

MEDIUM CVSS 4.3 Sep 17, 2025

This vulnerability is a reflected cross-site scripting (XSS) flaw in Portabilis i-Educar's agenda_preferencias.php file, where the tipoacao parameter is not properly sanitized. Attackers can inject ma...

CVE-2025-10607

MEDIUM CVSS 4.3 Sep 17, 2025

This vulnerability in Portabilis i-Educar allows unauthorized access to class information via the /module/Avaliacao/diarioApi endpoint. Attackers can remotely exploit this Broken Object Level Authoriz...

CVE-2025-10606

MEDIUM CVSS 4.3 Sep 17, 2025

This vulnerability allows attackers to inject malicious scripts into the Portabilis i-Educar web application via the 'tipoacao' parameter in the ConfiguracaoMovimentoGeral module. When exploited, this...

CVE-2025-10073

MEDIUM CVSS 4.3 Sep 8, 2025

This vulnerability in Portabilis i-Educar allows unauthorized access to class information through the /module/Api/turma endpoint. Attackers can exploit this broken object level authorization (BOLA) to...

CVE-2025-10071

MEDIUM CVSS 6.3 Sep 7, 2025

This vulnerability allows attackers to bypass access controls in Portabilis i-Educar's batch enrollment cancellation endpoint. Remote attackers can manipulate the /cancelar-enturmacao-em-lote/ endpoin...

CVE-2025-10072

MEDIUM CVSS 6.3 Sep 7, 2025

This vulnerability in Portabilis i-Educar allows attackers to bypass access controls on the student enrollment endpoint, potentially manipulating student class assignments without proper authorization...

CVE-2025-10070

MEDIUM CVSS 6.3 Sep 7, 2025

CVE-2025-10070 is an improper access control vulnerability in Portabilis i-Educar up to version 2.10 that allows remote attackers to bypass authorization mechanisms in the /enturmacao-em-lote/ endpoin...

CVE-2025-10012

MEDIUM CVSS 6.3 Sep 5, 2025

This CVE describes a SQL injection vulnerability in Portabilis i-Educar educational software versions up to 2.10. Attackers can exploit the 'ref_cod_aluno' parameter in the educar_historico_escolar_ls...

CVE-2025-9686

MEDIUM CVSS 6.3 Aug 30, 2025

This CVE describes a SQL injection vulnerability in Portabilis i-Educar's knowledge area listing page. Attackers can exploit this by manipulating the ID parameter in the /module/AreaConhecimento/edit ...

CVE-2025-9684

MEDIUM CVSS 6.3 Aug 30, 2025

This CVE describes a SQL injection vulnerability in Portabilis i-Educar's Formula de Cálculo de Média page. Attackers can exploit the 'ID' parameter in the /module/FormulaMedia/edit endpoint to exec...

CVE-2025-9607

MEDIUM CVSS 6.3 Aug 29, 2025

CVE-2025-9607 is a SQL injection vulnerability in Portabilis i-Educar's Tabelas de Arredondamento page that allows remote attackers to execute arbitrary SQL commands by manipulating the ID parameter. ...

CVE-2025-9532

MEDIUM CVSS 6.3 Aug 27, 2025

CVE-2025-9532 is a SQL injection vulnerability in Portabilis i-Educar educational software that allows remote attackers to execute arbitrary SQL commands via manipulation of the ID parameter in the /R...

CVE-2025-8789

MEDIUM CVSS 4.3 Aug 10, 2025

This vulnerability allows attackers to bypass authorization mechanisms in Portabilis i-Educar's API endpoint at /module/Api/Diario. Attackers can remotely exploit this to access unauthorized functiona...

CVE-2025-8790

MEDIUM CVSS 4.3 Aug 10, 2025

This vulnerability in Portabilis i-Educar allows attackers to bypass authorization controls by manipulating the ID parameter in the /module/Api/pessoa API endpoint. It affects all i-Educar installatio...

CVE-2025-8369

MEDIUM CVSS 4.3 Jul 31, 2025

This is a reflected cross-site scripting (XSS) vulnerability in Portabilis i-Educar 2.9 that allows attackers to inject malicious scripts via the 'titulo_avaliacao' parameter in the /intranet/educar_a...

CVE-2025-8367

MEDIUM CVSS 4.3 Jul 31, 2025

A reflected cross-site scripting (XSS) vulnerability exists in Portabilis i-Educar 2.9 where the 'nome' parameter in /intranet/funcionario_vinculo_lst.php is not properly sanitized. This allows attack...

CVE-2026-2064

LOW CVSS 3.5 Feb 6, 2026

This vulnerability allows attackers to inject malicious scripts into the User Data Page of Portabilis i-Educar through the /intranet/meusdadod.php file. The cross-site scripting (XSS) attack can be ex...