Generated remediation guidance and an executive summary. No account required.
MarkUs is a web application for the submission and grading of student assignments. Prior to version 2.9.1, the courses/<:course_id>/assignments/<:assignment_id>/submissions/html_content route reads the contents of a student-submitted file and renders them without sanitization. This issue has been patched in version 2.9.1.
Cite this page
CVE-2026-28405. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2026-28405
Use CWE-79, Markusproject vendor hub and Markus product page to widen CVE-2026-28405 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2026-25057, CVE-2024-51743 and CVE-2024-51499 for nearby disclosures in the same product family.