Vulnerability index

Browse CVEs

7 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Openedx CRITICAL 9.9
CVE-2026-42858

Open edX Platform enables the authoring and delivery of online learning at any scale. The sync_provider_data endpoint in SAMLProviderDataViewSet allo…

Fix: 2026-04-24+
Fix from $2,300 2026-05-11
Edx Enterprise HIGH 8.5
CVE-2026-42860

The Open edx Enterprise Service app provides enterprise features to the Open edX platform. From 7.0.2 to 7.0.4, the sync_provider_data endpoint in SA…

Fix: 7.0.5+
Fix from $1,950 2026-05-11
Openedx MEDIUM 5.4
CVE-2026-42857

Open edX Platform enables the authoring and delivery of online learning at any scale. The HTML sanitizer clean_thread_html_body() used for discussion…

Fix: 2026-04-24+
Fix from $1,600 2026-05-11
Openedx MEDIUM 6.1
CVE-2026-35404

Open edX Platform enables the authoring and delivery of online learning at any scale. The view_survey endpoint accepts a redirect_url GET parameter t…

Fix: after 2026-04-02
Fix from $1,600 2026-04-06
Openedx CRITICAL 9.8
CVE-2024-43782

This openedx-translations repository contains translation files from Open edX repositories to be kept in sync with Transifex. Before moving to pullin…

Patch available
Fix from $2,300 2024-08-23
Xblock Lti Consumer MEDIUM 5.4
CVE-2023-23611

LTI Consumer XBlock implements the consumer side of the LTI specification enabling integration of third-party LTI provider tools. Versions 7.0.0 and …

Fix: 7.2.2+
Fix from $1,600 2023-01-26
Xblock Drag And Drop V2 MEDIUM 6.1
CVE-2022-46147

Drag and Drop XBlock v2 implements a drag-and-drop style problem, where a learner has to drag items to zones on a target image. Versions prior to 3.0…

Fix: 3.0.0+
Fix from $1,600 2022-11-28