VYPR

Openedx

by Open.edx

Source repositories

CVEs (11)

  • CVE-2025-69784HigMar 16, 2026
    risk 0.57cvss 8.8epss 0.00

    A local, non-privileged attacker can abuse a vulnerable IOCTL interface exposed by the OpenEDR 2.5.1.0 kernel driver to modify the DLL injection path used by the product. By redirecting this path to a user-writable location, an attacker can cause OpenEDR to load an…

  • CVE-2020-13146HigMay 18, 2020
    risk 0.57cvss 8.8epss 0.01

    Studio in Open edX Ironwood 2.5 allows CSV injection because an added cohort in Course>Instructor>Cohorts may contain a formula that is exported via the "Course>Data Downloads>Reports>Download profile info" feature.

  • CVE-2025-69783HigMar 16, 2026
    risk 0.51cvss 7.8epss 0.00

    A local attacker can bypass OpenEDR's 2.5.1.0 self-defense mechanism by renaming a malicious executable to match a trusted process name (e.g., csrss.exe, edrsvc.exe, edrcon.exe). This allows unauthorized interaction with the OpenEDR kernel driver, granting access to privileged…

  • CVE-2026-42858HigMay 11, 2026
    risk 0.48cvss 8.5epss 0.00

    Open edX Platform enables the authoring and delivery of online learning at any scale. The sync_provider_data endpoint in SAMLProviderDataViewSet allows authenticated Enterprise Admin users to supply an arbitrary URL via the metadata_url POST parameter. This URL is passed…

  • CVE-2017-18381HigJul 30, 2019
    risk 0.47cvss 7.2epss 0.01

    The installation process in Open edX before 2017-01-10 exposes a MongoDB instance to external connections with default credentials.

  • CVE-2024-52452HigDec 2, 2024
    risk 0.46cvss 7.1epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in eduNEXT Open edX LMS allows Reflected XSS.This issue affects Open edX LMS: from n/a through 2.6.1.

  • CVE-2019-20513MedMar 19, 2020
    risk 0.40cvss 6.1epss 0.00

    Open edX Ironwood.1 allows support/certificates?user= reflected XSS.

  • CVE-2019-20512MedMar 18, 2020
    risk 0.40cvss 6.1epss 0.00

    Open edX Ironwood.1 allows support/certificates?course_id= reflected XSS.

  • CVE-2026-35404MedApr 6, 2026
    risk 0.24cvss 4.7epss 0.00

    Open edX Platform enables the authoring and delivery of online learning at any scale. The view_survey endpoint accepts a redirect_url GET parameter that is passed directly to HttpResponseRedirect() without any URL validation. When a non-existent survey name is provided, the…

  • CVE-2026-42857MedMay 11, 2026
    risk 0.23cvss 4.6epss 0.00

    Open edX Platform enables the authoring and delivery of online learning at any scale. The HTML sanitizer clean_thread_html_body() used for discussion notification emails fails to remove tags from user-generated discussion post content. This content is rendered with…

  • CVE-2024-43782HigAug 23, 2024
    risk 0.00cvss 7.7epss 0.01

    This openedx-translations repository contains translation files from Open edX repositories to be kept in sync with Transifex. Before moving to pulling translations from the openedx-translations repository via openedx-atlas, translations in the edx-platform repository were…