Vulnerability index

Browse CVEs

58 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Opensis MEDIUM 6.5
CVE-2026-11944

openSIS Classic 9.3 contains an authenticated path traversal vulnerability in the legacy messaging sent-mail attachment download functionality that a…

Mitigation only
Fix from $1,600 2026-07-14
Opensis CRITICAL 9.8
CVE-2021-41691

A SQL injection vulnerability exists in OS4Ed Open Source Information System Community v8.0 via the "student_id" and "TRANSFER{SCHOOL]" parameters in…

Mitigation only
Fix from $2,300 2025-06-24
Opensis CRITICAL 9.8
CVE-2024-51211

SQL injection vulnerability exists in OS4ED openSIS-Classic Version 9.1, specifically in the resetuserinfo.php file. The vulnerability is due to impr…

No fix yet
Fix from $2,300 2024-11-08
Opensis HIGH 8.8
CVE-2024-35584EPSS 6%

SQL injection vulnerabilities were discovered in Ajax.php, ForWindow.php, ForExport.php, Modules.php, functions/HackingLogFnc.php in OpenSis Communit…

No fix yet
Fix from $1,950 2024-10-15
Opensis HIGH 8.8
CVE-2024-46626

OS4ED openSIS-Classic v9.1 was discovered to contain a SQL injection vulnerability via a crafted payload.

No fix yet
Fix from $1,950 2024-10-02
Opensis CRITICAL 9.8
CVE-2023-38880

The Community Edition version 9.0 of OS4ED's openSIS Classic has a broken access control vulnerability in the database backup functionality. Whenever…

Mitigation only
Fix from $2,300 2023-11-20
Opensis HIGH 8.8
CVE-2023-38885

OpenSIS Classic Community Edition version 9.0 lacks cross-site request forgery (CSRF) protection throughout the whole app. This may allow an attacker…

Mitigation only
Fix from $1,950 2023-11-20
Opensis HIGH 7.5
CVE-2023-38879

The Community Edition version 9.0 of OS4ED's openSIS Classic allows remote attackers to read arbitrary files via a directory traversal vulnerability …

Mitigation only
Fix from $1,950 2023-11-20
Opensis HIGH 7.5
CVE-2023-38884

An Insecure Direct Object Reference (IDOR) vulnerability in the Community Edition version 9.0 of openSIS Classic allows an unauthenticated remote att…

Mitigation only
Fix from $1,950 2023-11-20
Opensis MEDIUM 6.1
CVE-2023-38881

A reflected cross-site scripting (XSS) vulnerability in the Community Edition version 9.0 of OS4ED's openSIS Classic allows remote attackers to execu…

Mitigation only
Fix from $1,600 2023-11-20
Opensis MEDIUM 6.1
CVE-2023-38882

A reflected cross-site scripting (XSS) vulnerability in the Community Edition version 9.0 of OS4ED's openSIS Classic allows remote attackers to execu…

Mitigation only
Fix from $1,600 2023-11-20
Opensis MEDIUM 6.1
CVE-2023-38883

A reflected cross-site scripting (XSS) vulnerability in the Community Edition version 9.0 of OS4ED's openSIS Classic allows remote attackers to execu…

Mitigation only
Fix from $1,600 2023-11-20
Opensis MEDIUM 6.1
CVE-2021-40637

OS4ED openSIS 8.0 is affected by cross-site scripting (XSS) in EmailCheckOthers.php. An attacker can inject JavaScript code to get the user's cookie …

No fix yet
Fix from $1,600 2022-03-03
Opensis HIGH 7.5
CVE-2021-40635

OS4ED openSIS 8.0 is affected by SQL injection in ChooseCpSearch.php, ChooseRequestSearch.php. An attacker can inject a SQL query to extract informat…

No fix yet
Fix from $1,950 2022-03-03
Opensis HIGH 7.5
CVE-2021-40636

OS4ED openSIS 8.0 is affected by SQL Injection in CheckDuplicateName.php, which can extract information from the database.

No fix yet
Fix from $1,950 2022-03-03
Opensis CRITICAL 9.8
CVE-2021-41679

A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database. An attacker can then issue …

No fix yet
Fix from $2,300 2021-11-30
Opensis CRITICAL 9.8
CVE-2021-41678

A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database. An attacker can then issue …

No fix yet
Fix from $2,300 2021-11-30
Opensis CRITICAL 9.8
CVE-2021-41677

A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database. An attacker can then issue …

No fix yet
Fix from $2,300 2021-11-30
Opensis CRITICAL 9.8
CVE-2021-40618

An SQL Injection vulnerability exists in openSIS Classic 8.0 via the 1) ADDR_CONT_USRN, 2) ADDR_CONT_PSWD, 3) SECN_CONT_USRN or 4) SECN_CONT_PSWD par…

No fix yet
Fix from $2,300 2021-10-12
Opensis CRITICAL 9.8
CVE-2021-40617EPSS 5%

An SQL Injection vulnerability exists in openSIS Community Edition version 8.0 via ForgotPassUserName.php.

No fix yet
Fix from $2,300 2021-10-11
Opensis CRITICAL 9.8
CVE-2021-40543

Opensis-Classic Version 8.0 is affected by a SQL injection vulnerability due to a lack of sanitization of input data at two parameters $_GET['usrid']…

No fix yet
Fix from $2,300 2021-10-11
Opensis MEDIUM 6.1
CVE-2021-40542

Opensis-Classic Version 8.0 is affected by cross-site scripting (XSS). An unauthenticated user can inject and execute JavaScript code through the lin…

No fix yet
Fix from $1,600 2021-10-11
Opensis MEDIUM 6.5
CVE-2021-40651EPSS 18%

OS4Ed OpenSIS Community 8.0 is vulnerable to a local file inclusion vulnerability in Modules.php (modname parameter), which can disclose arbitrary fi…

No fix yet
Fix from $1,600 2021-09-29
Opensis HIGH 8.8
CVE-2021-40309

A SQL injection vulnerability exists in the Take Attendance functionality of OS4Ed's OpenSIS 8.0. allows an attacker to inject their own SQL query. T…

No fix yet
Fix from $1,950 2021-09-24
Opensis MEDIUM 5.4
CVE-2021-40310

OpenSIS Community Edition version 8.0 is affected by a cross-site scripting (XSS) vulnerability in the TakeAttendance.php via the cp_id_miss_attn par…

No fix yet
Fix from $1,600 2021-09-24
Opensis CRITICAL 9.8
CVE-2021-39377

A SQL Injection vulnerability exists in openSIS 8.0 when MySQL (MariaDB) is being used as the application database. A malicious attacker can issue SQ…

No fix yet
Fix from $2,300 2021-09-01
Opensis CRITICAL 9.8
CVE-2021-39378EPSS 23%

A SQL Injection vulnerability exists in openSIS 8.0 when MySQL (MariaDB) is being used as the application database. A malicious attacker can issue SQ…

No fix yet
Fix from $2,300 2021-09-01
Opensis CRITICAL 9.8
CVE-2021-39379

A SQL Injection vulnerability exists in openSIS 8.0 when MySQL (MariaDB) is being used as the application database. A malicious attacker can issue SQ…

No fix yet
Fix from $2,300 2021-09-01
Opensis CRITICAL 9.8
CVE-2021-40353

A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database. An attacker can then issue …

No fix yet
Fix from $2,300 2021-09-01
Opensis CRITICAL 9.8
CVE-2020-6142EPSS 9%

A remote code execution vulnerability exists in the Modules.php functionality of OS4Ed openSIS 7.3. A specially crafted HTTP request can cause local …

No fix yet
Fix from $2,300 2020-09-01