Vulnerability index

Browse CVEs

19 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2024-22209 Open edX Platform is a service-oriented platform for authoring and delivering online learning. A user with a JWT and more limited scopes could call e… Edx Platform 2024-01-12+ Fix from $1,9502024-01-13 MEDIUM 6.1 CVE-2022-32195 Open edX platform before 2022-06-06 allows XSS via the "next" parameter in the logout URL. Open Edx 2022-06-06+ Fix from $1,6002022-06-09 MEDIUM 6.1 CVE-2021-39248 Open edX through Lilac.1 allows XSS in common/static/common/js/discussion/utils.js via crafted LaTeX content within a discussion. Edx Platform Patch available Fix from $1,6002021-08-17 HIGH 8.8 CVE-2020-13144EPSS 11% Studio in Open edX Ironwood 2.5, when CodeJail is not used, allows a user to go to the "Create New course>New section>New subsection>New unit>Add new… Open Edx Platform No fix yet Fix from $1,9502020-05-18 HIGH 8.8 CVE-2020-13146 Studio in Open edX Ironwood 2.5 allows CSV injection because an added cohort in Course>Instructor>Cohorts may contain a formula that is exported via … Open Edx Platform No fix yet Fix from $1,9502020-05-18 MEDIUM 5.4 CVE-2020-13145 Studio in Open edX Ironwood 2.5 allows users to upload SVG files via the "Content>File Uploads" screen. These files can contain JavaScript code and t… Open Edx Platform No fix yet Fix from $1,6002020-05-18 MEDIUM 6.1 CVE-2019-20513 Open edX Ironwood.1 allows support/certificates?user= reflected XSS. Open Edx No fix yet Fix from $1,6002020-03-19 MEDIUM 6.1 CVE-2018-20858 Recommender before 2018-07-18 allows XSS. Recommender 1.3.1+ Fix from $1,6002019-08-09 MEDIUM 6.1 CVE-2018-20859 edx-platform before 2018-07-18 allows XSS via a response to a Chemical Equation advanced problem. Edx Platform 2018-07-18+ Fix from $1,6002019-07-30 HIGH 7.2 CVE-2017-18381 The installation process in Open edX before 2017-01-10 exposes a MongoDB instance to external connections with default credentials. Edx Platform 2017-01-10+ Fix from $1,9502019-07-30 HIGH 7.5 CVE-2017-18380 edx-platform before 2017-08-03 allows attackers to trigger password-reset e-mail messages in which the reset link has an attacker-controlled domain n… Edx Platform 2017-08-03+ Fix from $1,9502019-07-30 HIGH 8.8 CVE-2016-10766 edx-platform before 2016-06-06 allows CSRF. Edx Platform 2016-06-06+ Fix from $1,9502019-07-29 MEDIUM 5.3 CVE-2016-10765 edx-platform before 2016-06-10 allows account activation with a spoofed e-mail address. Edx Platform 2016-06-10+ Fix from $1,6002019-07-29 MEDIUM 6.1 CVE-2015-6960 edx-platform before 2015-09-17 allows XSS via a team name. Edx Platform 2015-09-17+ Fix from $1,6002019-07-29 MEDIUM 5.4 CVE-2015-6253 edx-platform before 2015-08-17 allows XSS in the Studio listing of courses. Edx Platform 2015-08-17+ Fix from $1,6002019-07-29 HIGH 8.8 CVE-2015-5601 edx-platform before 2015-07-20 allows code execution by privileged users because the course import endpoint mishandles .tar.gz files. Edx Platform 2015-07-20+ Fix from $1,9502019-07-29 HIGH 7.5 CVE-2015-2186 The Ansible edxapp role in the Configuration Repo in edX allows remote websites to spoof edX accounts by leveraging use of the string literal "False"… Configuration after 1.6.0 Fix from $1,9502018-02-03 MEDIUM 5.9 CVE-2015-6671 Open edX edx-platform before 2015-08-25 requires use of the database for storage of SAML SSO secrets, which makes it easier for context-dependent att… Edx Platform after 2015-08-20 Fix from $1,6002017-03-13 MEDIUM 6.5 CVE-2015-2286 lms/templates/footer-edx-new.html in Open edX edx-platform before 2015-01-29 does not properly restrict links on the password-reset page, which allow… Open Edx after 2015-01-27 Fix from $1,6002016-03-19