Vulnerability index

Browse CVEs

81 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2026-11944 openSIS Classic 9.3 contains an authenticated path traversal vulnerability in the legacy messaging sent-mail attachment download functionality that a… Opensis Mitigation only Fix from $1,6002026-07-14 HIGH 8.1 CVE-2025-65594 OpenSIS 9.2 and below is vulnerable to Incorrect Access Control in Student.php, which allows an authenticated low-privilege user to perform unauthori… Opensis after 9.2 Fix from $1,9502025-12-09 HIGH 8.1 CVE-2025-26186 SQL Injection vulnerability in openSIS v.9.1 allows a remote attacker to execute arbitrary code via the id parameter in Ajax.php Opensis Patch available Fix from $1,9502025-07-15 CRITICAL 9.8 CVE-2021-41691 A SQL injection vulnerability exists in OS4Ed Open Source Information System Community v8.0 via the "student_id" and "TRANSFER{SCHOOL]" parameters in… Opensis Mitigation only Fix from $2,3002025-06-24 CRITICAL 9.8 CVE-2025-22926 An issue in OS4ED openSIS v8.0 through v9.1 allows attackers to execute a directory traversal by sending a crafted POST request to /Modules.php?modna… Opensis after 9.1 Fix from $2,3002025-04-03 CRITICAL 9.8 CVE-2025-22929 OS4ED openSIS v7.0 to v9.1 was discovered to contain a SQL injection vulnerability via the filter_id parameter at /students/StudentFilters.php. Opensis after 9.1 Fix from $2,3002025-04-03 CRITICAL 9.8 CVE-2025-22930 OS4ED openSIS v7.0 to v9.1 was discovered to contain a SQL injection vulnerability via the groupid parameter at /messaging/Group.php. Opensis after 9.1 Fix from $2,3002025-04-03 HIGH 7.5 CVE-2025-22931 An insecure direct object reference (IDOR) in the component /assets/stafffiles of OS4ED openSIS v7.0 to v9.1 allows unauthenticated attackers to acce… Opensis after 9.1 Fix from $1,9502025-04-03 CRITICAL 9.8 CVE-2025-22928 OS4ED openSIS v7.0 to v9.1 was discovered to contain a SQL injection vulnerability via the cp_id parameter at /modules/messages/Inbox.php. Opensis after 9.1 Fix from $2,3002025-04-03 CRITICAL 9.1 CVE-2025-22927 An issue in OS4ED openSIS v8.0 through v9.1 allows attackers to execute a directory traversal by sending a crafted POST request to /Modules.php?modna… Opensis after 9.1 Fix from $2,3002025-04-03 HIGH 8.8 CVE-2025-22923 An issue in OS4ED openSIS v8.0 through v9.1 allows attackers to execute a directory traversal and delete files by sending a crafted POST request to /… Opensis after 9.1 Fix from $1,9502025-04-02 HIGH 8.8 CVE-2025-22924 OS4ED openSIS v7.0 through v9.1 contains a SQL injection vulnerability via the stu_id parameter at /modules/students/Student.php. Opensis after 9.1 Fix from $1,9502025-04-02 HIGH 7.5 CVE-2025-22925 OS4ED openSIS v7.0 to v9.1 was discovered to contain a SQL injection vulnerability via the table parameter at /attendance/AttendanceCodes.php. The re… Opensis after 9.1 Fix from $1,9502025-04-02 CRITICAL 9.8 CVE-2024-51211 SQL injection vulnerability exists in OS4ED openSIS-Classic Version 9.1, specifically in the resetuserinfo.php file. The vulnerability is due to impr… Opensis No fix yet Fix from $2,3002024-11-08 HIGH 8.8 CVE-2024-35584EPSS 6% SQL injection vulnerabilities were discovered in Ajax.php, ForWindow.php, ForExport.php, Modules.php, functions/HackingLogFnc.php in OpenSis Communit… Opensis No fix yet Fix from $1,9502024-10-15 HIGH 8.8 CVE-2024-46626 OS4ED openSIS-Classic v9.1 was discovered to contain a SQL injection vulnerability via a crafted payload. Opensis No fix yet Fix from $1,9502024-10-02 CRITICAL 9.8 CVE-2023-38880 The Community Edition version 9.0 of OS4ED's openSIS Classic has a broken access control vulnerability in the database backup functionality. Whenever… Opensis Mitigation only Fix from $2,3002023-11-20 HIGH 8.8 CVE-2023-38885 OpenSIS Classic Community Edition version 9.0 lacks cross-site request forgery (CSRF) protection throughout the whole app. This may allow an attacker… Opensis Mitigation only Fix from $1,9502023-11-20 HIGH 7.5 CVE-2023-38879 The Community Edition version 9.0 of OS4ED's openSIS Classic allows remote attackers to read arbitrary files via a directory traversal vulnerability … Opensis Mitigation only Fix from $1,9502023-11-20 HIGH 7.5 CVE-2023-38884 An Insecure Direct Object Reference (IDOR) vulnerability in the Community Edition version 9.0 of openSIS Classic allows an unauthenticated remote att… Opensis Mitigation only Fix from $1,9502023-11-20 MEDIUM 6.1 CVE-2023-38881 A reflected cross-site scripting (XSS) vulnerability in the Community Edition version 9.0 of OS4ED's openSIS Classic allows remote attackers to execu… Opensis Mitigation only Fix from $1,6002023-11-20 MEDIUM 6.1 CVE-2023-38882 A reflected cross-site scripting (XSS) vulnerability in the Community Edition version 9.0 of OS4ED's openSIS Classic allows remote attackers to execu… Opensis Mitigation only Fix from $1,6002023-11-20 MEDIUM 6.1 CVE-2023-38883 A reflected cross-site scripting (XSS) vulnerability in the Community Edition version 9.0 of OS4ED's openSIS Classic allows remote attackers to execu… Opensis Mitigation only Fix from $1,6002023-11-20 MEDIUM 6.5 CVE-2022-45962 Open Solutions for Education, Inc openSIS Community Edition v8.0 and earlier is vulnerable to SQL Injection via CalendarModal.php. Opensis after 8.0 Fix from $1,6002023-02-13 HIGH 7.5 CVE-2022-27041 Due to lack of protection, parameter student_id in OpenSIS Classic 8.0 /modules/eligibility/Student.php can be used to inject SQL queries to extract … Opensis Patch available Fix from $1,9502022-04-11 MEDIUM 6.1 CVE-2021-40637 OS4ED openSIS 8.0 is affected by cross-site scripting (XSS) in EmailCheckOthers.php. An attacker can inject JavaScript code to get the user's cookie … Opensis No fix yet Fix from $1,6002022-03-03 HIGH 7.5 CVE-2021-40635 OS4ED openSIS 8.0 is affected by SQL injection in ChooseCpSearch.php, ChooseRequestSearch.php. An attacker can inject a SQL query to extract informat… Opensis No fix yet Fix from $1,9502022-03-03 HIGH 7.5 CVE-2021-40636 OS4ED openSIS 8.0 is affected by SQL Injection in CheckDuplicateName.php, which can extract information from the database. Opensis No fix yet Fix from $1,9502022-03-03 CRITICAL 9.8 CVE-2021-41679 A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database. An attacker can then issue … Opensis No fix yet Fix from $2,3002021-11-30 CRITICAL 9.8 CVE-2021-41678 A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database. An attacker can then issue … Opensis No fix yet Fix from $2,3002021-11-30