Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2024-22209
Open edX Platform is a service-oriented platform for authoring and delivering online learning. A user with a JWT and more limited scopes could call e…
Edx Platform
2024-01-12+
MEDIUM 6.1
CVE-2022-32195
Open edX platform before 2022-06-06 allows XSS via the "next" parameter in the logout URL.
Open Edx
2022-06-06+
MEDIUM 6.1
CVE-2021-39248
Open edX through Lilac.1 allows XSS in common/static/common/js/discussion/utils.js via crafted LaTeX content within a discussion.
Edx Platform
Patch available
HIGH 8.8
CVE-2020-13144EPSS 11%
Studio in Open edX Ironwood 2.5, when CodeJail is not used, allows a user to go to the "Create New course>New section>New subsection>New unit>Add new…
Open Edx Platform
No fix yet
HIGH 8.8
CVE-2020-13146
Studio in Open edX Ironwood 2.5 allows CSV injection because an added cohort in Course>Instructor>Cohorts may contain a formula that is exported via …
Open Edx Platform
No fix yet
MEDIUM 5.4
CVE-2020-13145
Studio in Open edX Ironwood 2.5 allows users to upload SVG files via the "Content>File Uploads" screen. These files can contain JavaScript code and t…
Open Edx Platform
No fix yet
MEDIUM 6.1
CVE-2019-20513
Open edX Ironwood.1 allows support/certificates?user= reflected XSS.
Open Edx
No fix yet
MEDIUM 6.1
CVE-2018-20858
Recommender before 2018-07-18 allows XSS.
Recommender
1.3.1+
MEDIUM 6.1
CVE-2018-20859
edx-platform before 2018-07-18 allows XSS via a response to a Chemical Equation advanced problem.
Edx Platform
2018-07-18+
HIGH 7.2
CVE-2017-18381
The installation process in Open edX before 2017-01-10 exposes a MongoDB instance to external connections with default credentials.
Edx Platform
2017-01-10+
HIGH 7.5
CVE-2017-18380
edx-platform before 2017-08-03 allows attackers to trigger password-reset e-mail messages in which the reset link has an attacker-controlled domain n…
Edx Platform
2017-08-03+
HIGH 8.8
CVE-2016-10766
edx-platform before 2016-06-06 allows CSRF.
Edx Platform
2016-06-06+
MEDIUM 5.3
CVE-2016-10765
edx-platform before 2016-06-10 allows account activation with a spoofed e-mail address.
Edx Platform
2016-06-10+
MEDIUM 6.1
CVE-2015-6960
edx-platform before 2015-09-17 allows XSS via a team name.
Edx Platform
2015-09-17+
MEDIUM 5.4
CVE-2015-6253
edx-platform before 2015-08-17 allows XSS in the Studio listing of courses.
Edx Platform
2015-08-17+
HIGH 8.8
CVE-2015-5601
edx-platform before 2015-07-20 allows code execution by privileged users because the course import endpoint mishandles .tar.gz files.
Edx Platform
2015-07-20+
HIGH 7.5
CVE-2015-2186
The Ansible edxapp role in the Configuration Repo in edX allows remote websites to spoof edX accounts by leveraging use of the string literal "False"…
Configuration
after 1.6.0
MEDIUM 5.9
CVE-2015-6671
Open edX edx-platform before 2015-08-25 requires use of the database for storage of SAML SSO secrets, which makes it easier for context-dependent att…
Edx Platform
after 2015-08-20
MEDIUM 6.5
CVE-2015-2286
lms/templates/footer-edx-new.html in Open edX edx-platform before 2015-01-29 does not properly restrict links on the password-reset page, which allow…
Open Edx
after 2015-01-27