VYPR

Open edX Platform

by Open EdX Platform

CVEs (10)

  • CVE-2015-5601HigJul 29, 2019
    risk 0.57cvss 8.8epss 0.01

    edx-platform before 2015-07-20 allows code execution by privileged users because the course import endpoint mishandles .tar.gz files.

  • CVE-2026-42858HigMay 11, 2026
    risk 0.48cvss 8.5epss 0.00

    Open edX Platform enables the authoring and delivery of online learning at any scale. The sync_provider_data endpoint in SAMLProviderDataViewSet allows authenticated Enterprise Admin users to supply an arbitrary URL via the metadata_url POST parameter. This URL is passed…

  • CVE-2015-6960MedJul 29, 2019
    risk 0.40cvss 6.1epss 0.01

    edx-platform before 2015-09-17 allows XSS via a team name.

  • CVE-2015-6253MedJul 29, 2019
    risk 0.35cvss 5.4epss 0.01

    edx-platform before 2015-08-17 allows XSS in the Studio listing of courses.

  • CVE-2016-10765MedJul 29, 2019
    risk 0.28cvss 5.3epss 0.01

    edx-platform before 2016-06-10 allows account activation with a spoofed e-mail address.

  • CVE-2026-34736MedApr 2, 2026
    risk 0.27cvss 5.3epss 0.00

    Open edX Platform enables the authoring and delivery of online learning at any scale. From the maple release to before the ulmo release, an unauthenticated attacker can fully bypass the email verification process by combining two issues: the OAuth2 password grant issuing tokens…

  • CVE-2026-53636MedSep 2, 2026
    risk 0.24cvss 4.7epss

    Open edX Platform enables the authoring and delivery of online learning at any scale. Prior to commit 3a5ac85, a security vulnerability has been identified in the Open edX LMS platform's LTI (Learning Tools Interoperability) Provider implementation. The…

  • CVE-2026-35404MedApr 6, 2026
    risk 0.24cvss 4.7epss 0.00

    Open edX Platform enables the authoring and delivery of online learning at any scale. The view_survey endpoint accepts a redirect_url GET parameter that is passed directly to HttpResponseRedirect() without any URL validation. When a non-existent survey name is provided, the…

  • CVE-2026-42857MedMay 11, 2026
    risk 0.23cvss 4.6epss 0.00

    Open edX Platform enables the authoring and delivery of online learning at any scale. The HTML sanitizer clean_thread_html_body() used for discussion notification emails fails to remove tags from user-generated discussion post content. This content is rendered with…

  • CVE-2024-22209MedJan 13, 2024
    risk 0.00cvss 6.4epss 0.01

    Open edX Platform is a service-oriented platform for authoring and delivering online learning. A user with a JWT and more limited scopes could call endpoints exceeding their access. This vulnerability has been patched in commit 019888f.