Portabilis Security Vulnerabilities (CVEs)
Track 32 security vulnerabilities affecting Portabilis products and software. Get instant email alerts when new CVEs are discovered, automated security monitoring, and patch guidance.
This vulnerability allows attackers to inject malicious scripts into the User Data Page of Portabilis i-Educar through the /intranet/meusdadod.php fil...
Feb 6, 2026This stored XSS vulnerability in Portabilis i-Educar allows attackers to inject malicious scripts via the matricula_interna parameter, which are then ...
Dec 9, 2025An authenticated time-based SQL injection vulnerability in i-Educar school management software allows attackers with valid user credentials to execute...
Nov 19, 2025An authenticated time-based SQL injection vulnerability in i-Educar school management software allows attackers with valid user sessions to execute ar...
Nov 19, 2025This vulnerability in Portabilis i-Educar allows attackers to escalate privileges through insecure inherited permissions in the User Type Handler comp...
Oct 9, 2025CVE-2025-11050 is an improper authorization vulnerability in Portabilis i-Educar's /periodo-lancamento endpoint that allows remote attackers to bypass...
Sep 27, 2025CVE-2025-11049 is an improper authorization vulnerability in Portabilis i-Educar's /unificacao-aluno endpoint that allows unauthorized access to stude...
Sep 27, 2025This vulnerability allows attackers to bypass authorization controls in Portabilis i-Educar's /consulta-dispensas endpoint, potentially accessing unau...
Sep 26, 2025This vulnerability in Portabilis i-Educar allows attackers to bypass authorization controls and enumerate student records by manipulating the aluno_id...
Sep 26, 2025This SQL injection vulnerability in Portabilis i-Educar allows attackers to execute arbitrary SQL commands through the /module/Cadastro/aluno endpoint...
Sep 23, 2025This SQL injection vulnerability in Portabilis i-Educar allows attackers to execute arbitrary SQL commands by manipulating the ID parameter in the /mo...
Sep 23, 2025This SQL injection vulnerability in Portabilis i-Educar allows attackers to manipulate database queries through the /module/ComponenteCurricular/edit ...
Sep 23, 2025This vulnerability in Portabilis i-Educar allows attackers to bypass access controls on the /enrollment-history/ endpoint, potentially accessing unaut...
Sep 17, 2025This vulnerability is a reflected cross-site scripting (XSS) flaw in Portabilis i-Educar's agenda_preferencias.php file, where the tipoacao parameter ...
Sep 17, 2025This vulnerability allows attackers to inject malicious scripts into the Portabilis i-Educar web application via the 'tipoacao' parameter in the Confi...
Sep 17, 2025This vulnerability in Portabilis i-Educar allows unauthorized access to class information via the /module/Avaliacao/diarioApi endpoint. Attackers can ...
Sep 17, 2025This vulnerability in Portabilis i-Educar allows unauthorized access to class information through the /module/Api/turma endpoint. Attackers can exploi...
Sep 8, 2025This vulnerability allows attackers to bypass access controls in Portabilis i-Educar's batch enrollment cancellation endpoint. Remote attackers can ma...
Sep 7, 2025This vulnerability in Portabilis i-Educar allows attackers to bypass access controls on the student enrollment endpoint, potentially manipulating stud...
Sep 7, 2025CVE-2025-10070 is an improper access control vulnerability in Portabilis i-Educar up to version 2.10 that allows remote attackers to bypass authorizat...
Sep 7, 2025This CVE describes a SQL injection vulnerability in Portabilis i-Educar educational software versions up to 2.10. Attackers can exploit the 'ref_cod_a...
Sep 5, 2025This CVE describes a SQL injection vulnerability in Portabilis i-Educar's knowledge area listing page. Attackers can exploit this by manipulating the ...
Aug 30, 2025This CVE describes a SQL injection vulnerability in Portabilis i-Educar's Formula de Cálculo de Média page. Attackers can exploit the 'ID' parameter...
Aug 30, 2025CVE-2025-9607 is a SQL injection vulnerability in Portabilis i-Educar's Tabelas de Arredondamento page that allows remote attackers to execute arbitra...
Aug 29, 2025CVE-2025-9532 is a SQL injection vulnerability in Portabilis i-Educar educational software that allows remote attackers to execute arbitrary SQL comma...
Aug 27, 2025This vulnerability allows attackers to inject malicious scripts into the Portabilis i-Diario web application through the search_autocomplete endpoint....
Aug 18, 2025This vulnerability allows attackers to bypass authorization mechanisms in Portabilis i-Educar's API endpoint at /module/Api/Diario. Attackers can remo...
Aug 10, 2025This vulnerability in Portabilis i-Educar allows attackers to bypass authorization controls by manipulating the ID parameter in the /module/Api/pessoa...
Aug 10, 2025This is a reflected cross-site scripting (XSS) vulnerability in Portabilis i-Educar 2.9 that allows attackers to inject malicious scripts via the 'tit...
Jul 31, 2025A reflected cross-site scripting (XSS) vulnerability exists in Portabilis i-Educar 2.9 where the 'nome' parameter in /intranet/funcionario_vinculo_lst...
Jul 31, 2025CVE-2024-48325 is an unauthenticated SQL injection vulnerability in Portabilis i-Educar 2.8.0 that allows remote attackers to execute arbitrary SQL co...
Nov 6, 2024This vulnerability allows authenticated users with minimal viewing privileges in i-Educar school management software to escalate their privileges to A...
Aug 28, 2024Why Monitor Portabilis Security Vulnerabilities?
Real-time CVE tracking: Our automated system monitors 32+ known vulnerabilities affecting Portabilis products and software packages. Stay ahead of emerging threats with instant email notifications when new security issues are discovered.
Automated security monitoring: Unlike manual CVE checking, FixTheCVE automatically scans your servers and detects vulnerable Portabilis packages in under 60 seconds. No agents required - completely agentless scanning that works across Portabilis deployments.
Free vulnerability database: Access detailed information about every Portabilis CVE including CVSS scores, severity ratings, affected versions, and actionable patch guidance. Filter by critical, high, medium, or low severity to prioritize your security remediation efforts.
🚀 Get Started in 60 Seconds
- Register free account & add your servers
- Run one-time scan or schedule automatic monitoring (every 1-24 hours)
- Receive instant alerts when new Portabilis CVEs affect your systems
- Access dashboard with severity breakdown & fix instructions