Vulnerability index

Browse CVEs

19 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Edx Platform HIGH 8.8
CVE-2024-22209

Open edX Platform is a service-oriented platform for authoring and delivering online learning. A user with a JWT and more limited scopes could call e…

Fix: 2024-01-12+
Fix from $1,950 2024-01-13
Open Edx MEDIUM 6.1
CVE-2022-32195

Open edX platform before 2022-06-06 allows XSS via the "next" parameter in the logout URL.

Fix: 2022-06-06+
Fix from $1,600 2022-06-09
Edx Platform MEDIUM 6.1
CVE-2021-39248

Open edX through Lilac.1 allows XSS in common/static/common/js/discussion/utils.js via crafted LaTeX content within a discussion.

Patch available
Fix from $1,600 2021-08-17
Open Edx Platform HIGH 8.8
CVE-2020-13144EPSS 11%

Studio in Open edX Ironwood 2.5, when CodeJail is not used, allows a user to go to the "Create New course>New section>New subsection>New unit>Add new…

No fix yet
Fix from $1,950 2020-05-18
Open Edx Platform HIGH 8.8
CVE-2020-13146

Studio in Open edX Ironwood 2.5 allows CSV injection because an added cohort in Course>Instructor>Cohorts may contain a formula that is exported via …

No fix yet
Fix from $1,950 2020-05-18
Open Edx Platform MEDIUM 5.4
CVE-2020-13145

Studio in Open edX Ironwood 2.5 allows users to upload SVG files via the "Content>File Uploads" screen. These files can contain JavaScript code and t…

No fix yet
Fix from $1,600 2020-05-18
Open Edx MEDIUM 6.1
CVE-2019-20513

Open edX Ironwood.1 allows support/certificates?user= reflected XSS.

No fix yet
Fix from $1,600 2020-03-19
Recommender MEDIUM 6.1
CVE-2018-20858

Recommender before 2018-07-18 allows XSS.

Fix: 1.3.1+
Fix from $1,600 2019-08-09
Edx Platform MEDIUM 6.1
CVE-2018-20859

edx-platform before 2018-07-18 allows XSS via a response to a Chemical Equation advanced problem.

Fix: 2018-07-18+
Fix from $1,600 2019-07-30
Edx Platform HIGH 7.2
CVE-2017-18381

The installation process in Open edX before 2017-01-10 exposes a MongoDB instance to external connections with default credentials.

Fix: 2017-01-10+
Fix from $1,950 2019-07-30
Edx Platform HIGH 7.5
CVE-2017-18380

edx-platform before 2017-08-03 allows attackers to trigger password-reset e-mail messages in which the reset link has an attacker-controlled domain n…

Fix: 2017-08-03+
Fix from $1,950 2019-07-30
Edx Platform HIGH 8.8
CVE-2016-10766

edx-platform before 2016-06-06 allows CSRF.

Fix: 2016-06-06+
Fix from $1,950 2019-07-29
Edx Platform MEDIUM 5.3
CVE-2016-10765

edx-platform before 2016-06-10 allows account activation with a spoofed e-mail address.

Fix: 2016-06-10+
Fix from $1,600 2019-07-29
Edx Platform MEDIUM 6.1
CVE-2015-6960

edx-platform before 2015-09-17 allows XSS via a team name.

Fix: 2015-09-17+
Fix from $1,600 2019-07-29
Edx Platform MEDIUM 5.4
CVE-2015-6253

edx-platform before 2015-08-17 allows XSS in the Studio listing of courses.

Fix: 2015-08-17+
Fix from $1,600 2019-07-29
Edx Platform HIGH 8.8
CVE-2015-5601

edx-platform before 2015-07-20 allows code execution by privileged users because the course import endpoint mishandles .tar.gz files.

Fix: 2015-07-20+
Fix from $1,950 2019-07-29
Configuration HIGH 7.5
CVE-2015-2186

The Ansible edxapp role in the Configuration Repo in edX allows remote websites to spoof edX accounts by leveraging use of the string literal "False"…

Fix: after 1.6.0
Fix from $1,950 2018-02-03
Edx Platform MEDIUM 5.9
CVE-2015-6671

Open edX edx-platform before 2015-08-25 requires use of the database for storage of SAML SSO secrets, which makes it easier for context-dependent att…

Fix: after 2015-08-20
Fix from $1,600 2017-03-13
Open Edx MEDIUM 6.5
CVE-2015-2286

lms/templates/footer-edx-new.html in Open edX edx-platform before 2015-01-29 does not properly restrict links on the password-reset page, which allow…

Fix: after 2015-01-27
Fix from $1,600 2016-03-19