Loading market data...
← Back to CVE feed

CVE-2026-31281

UNKNOWN View on NVD ↗

Description

Totara LMS v19.1.5 and before is vulnerable to HTLM Injection. An attacker can inject malicious HTLM code in a message and send it to all the users in the application, resulting in executing the code and may lead to session hijacking and executing commands on the victim's browser.

Published: Apr 13, 2026 15:17 UTC Modified: Apr 13, 2026 15:17 UTC