📦 Markus

by Markusproject

🔍 What is Markus?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2026-25057

CRITICAL CVSS 9.1 Feb 9, 2026

This vulnerability allows instructors to achieve arbitrary file write on the server by uploading specially crafted zip files. Attackers could write malicious files anywhere the application has write p...

CVE-2024-51743

HIGH CVSS 8.8 Nov 18, 2024

This vulnerability allows authenticated instructors in MarkUs to write arbitrary files to any location on the web server, potentially leading to remote code execution. It affects MarkUs versions prior...

CVE-2026-24900

MEDIUM CVSS 6.5 Feb 9, 2026

MarkUs versions before 2.9.1 contain an authorization bypass vulnerability where users can access arbitrary student submission files by manipulating the select_file_id parameter. This allows unauthori...