Vulnerability index

Browse CVEs

16 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Blackboard Learn MEDIUM 6.5
CVE-2022-39196

Blackboard Learn 1.10.1 allows remote authenticated users to read unintended files by entering student credentials and then directly visiting a certa…

No fix yet
Fix from $1,600 2022-09-05
Blackboard Learn MEDIUM 5.4
CVE-2021-36746

Blackboard Learn through 9.1 allows XSS by an authenticated user via the Assignment Instructions HTML editor.

Fix: after 9.1
Fix from $1,600 2021-07-20
Blackboard Learn MEDIUM 5.4
CVE-2021-36747

Blackboard Learn through 9.1 allows XSS by an authenticated user via the Feedback to Learner form.

Fix: after 9.1
Fix from $1,600 2021-07-20
Collaborate Ultra MEDIUM 6.1
CVE-2020-25902

Blackboard Collaborate Ultra 20.02 is affected by a cross-site scripting (XSS) vulnerability. The XSS payload will execute on the class room, which l…

Mitigation only
Fix from $1,600 2021-03-02
Blackboard Learn MEDIUM 5.4
CVE-2020-9008

Stored Cross-site scripting (XSS) vulnerability in Blackboard Learn/PeopleTool v9.1 allows users to inject arbitrary web script via the Tile widget i…

Fix: 9.1+
Fix from $1,600 2020-02-25
Blackboard Learn MEDIUM 6.1
CVE-2018-13257

The bb-auth-provider-cas authentication module within Blackboard Learn 2018-07-02 is susceptible to HTTP host header spoofing during Central Authenti…

No fix yet
Fix from $1,600 2019-11-18
Blackboard Learn MEDIUM 6.1
CVE-2017-18262

Blackboard Learn (Since at least 17th of October 2017) has allowed Unvalidated Redirects on any signed-in user through its endpoints for handling Shi…

Fix: after 9.1
Fix from $1,600 2018-04-30
Blackboard Academic Suite MEDIUM 6.8
CVE-2008-1883

The server in Blackboard Academic Suite 7.x stores MD5 password hashes that are provided directly by clients, which makes it easier for remote attack…

Fix: after 7
Fix from $1,600 2008-04-18
Blackboard Academic Suite MEDIUM 6.0
CVE-2006-3914

Cross-site scripting (XSS) vulnerability in Blackboard Academic Suite 6.2.3.23 allows remote authenticated users to inject arbitrary HTML or web scri…

Mitigation only
Fix from $1,600 2006-07-28
Academic Suite HIGH 10.0
CVE-2005-4338

announcement.pl in Blackboard Learning and Community Portal System in Academic Suite 6.3.1.424, 6.2.3.23, and other versions before 6 allows remote a…

No fix yet
Fix from $1,950 2005-12-19
Academic Suite HIGH 7.5
CVE-2005-4337

The login page in Blackboard Learning and Community Portal System in Academic Suite 6.3.1.424, 6.2.3.23, and other versions before 6 allows remote at…

No fix yet
Fix from $1,950 2005-12-19
Academic Suite MEDIUM 5.0
CVE-2005-4341

Blackboard Learning and Community Portal System in Academic Suite 6.3.1.424, 6.2.3.23, and other versions before 6 allows remote attackers to list al…

Mitigation only
Fix from $1,600 2005-12-19
Academic Suite MEDIUM 6.1
CVE-2005-4206

Blackboard Learning and Community Portal System in Academic Suite 6.3.1.424, 6.2.3.23, and other versions before 6 allows remote attackers to redirec…

Fix: after 6.0.0.0
Fix from $1,600 2005-12-13
Blackboard MEDIUM 5.0
CVE-2004-1581

BlackBoard 1.5.1 allows remote attackers to gain sensitive information via a direct request to (1) checkdb.inc.php, (2) admin.inc.php or (3) cp.inc.p…

Mitigation only
Fix from $1,600 2004-12-31
Blackboard HIGH 7.5
CVE-2002-1007

Cross-site scripting vulnerabilities in Blackboard 5 allow remote attackers to execute arbitrary web script via (1) the course_id parameter in a link…

No fix yet
Fix from $1,950 2002-10-04
Courseinfo HIGH 7.5
CVE-2000-0627

BlackBoard CourseInfo 4.0 does not properly authenticate users, which allows local users to modify CourseInfo database information and gain privilege…

Patch available
Fix from $1,950 2000-07-18