CVE-2026-97864 is a missing authentication vulnerability in GibbonEdu Gibbon up to 30.0.01, specifically in the makeBlock function of modules/Planner/units_add_blockAjax.php. The vulnerability allows remote attacks. Upgrading to version 31.0.00 fixes this issue, with patch 07e719368eae8dfb4e22e19424ceab6074164ebc. The CVE record was published on 2026-09-25T14:17:27.217Z and has not been modified since then.
CVE-2026-8209 is an authenticated path traversal issue in Gibbon versions before v30.0.01. According to the CVE record, a user with Teacher or higher privileges can trigger archive extraction against web application PHP files; if .zip extraction fails, a file can be deleted, leading to denial of service and loss of application availability. The referenced GibbonEdu v30.0.01 release is the fixed version.