Open EdX Platform
Products
1- 10 CVEs
Recent CVEs
10| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2015-5601 | Hig | 0.57 | 8.8 | 0.01 | Jul 29, 2019 | edx-platform before 2015-07-20 allows code execution by privileged users because the course import endpoint mishandles .tar.gz files. | ||
| CVE-2026-42858 | Hig | 0.48 | 8.5 | 0.00 | May 11, 2026 | Open edX Platform enables the authoring and delivery of online learning at any scale. The sync_provider_data endpoint in SAMLProviderDataViewSet allows authenticated Enterprise Admin users to supply an arbitrary URL via the metadata_url POST parameter. This URL is passed… | ||
| CVE-2015-6960 | Med | 0.40 | 6.1 | 0.01 | Jul 29, 2019 | edx-platform before 2015-09-17 allows XSS via a team name. | ||
| CVE-2015-6253 | Med | 0.35 | 5.4 | 0.01 | Jul 29, 2019 | edx-platform before 2015-08-17 allows XSS in the Studio listing of courses. | ||
| CVE-2016-10765 | Med | 0.28 | 5.3 | 0.01 | Jul 29, 2019 | edx-platform before 2016-06-10 allows account activation with a spoofed e-mail address. | ||
| CVE-2026-34736 | Med | 0.27 | 5.3 | 0.00 | Apr 2, 2026 | Open edX Platform enables the authoring and delivery of online learning at any scale. From the maple release to before the ulmo release, an unauthenticated attacker can fully bypass the email verification process by combining two issues: the OAuth2 password grant issuing tokens… | ||
| CVE-2026-53636 | Med | 0.24 | 4.7 | — | Sep 2, 2026 | Open edX Platform enables the authoring and delivery of online learning at any scale. Prior to commit 3a5ac85, a security vulnerability has been identified in the Open edX LMS platform's LTI (Learning Tools Interoperability) Provider implementation. The… | ||
| CVE-2026-35404 | Med | 0.24 | 4.7 | 0.00 | Apr 6, 2026 | Open edX Platform enables the authoring and delivery of online learning at any scale. The view_survey endpoint accepts a redirect_url GET parameter that is passed directly to HttpResponseRedirect() without any URL validation. When a non-existent survey name is provided, the… | ||
| CVE-2026-42857 | Med | 0.23 | 4.6 | 0.00 | May 11, 2026 | Open edX Platform enables the authoring and delivery of online learning at any scale. The HTML sanitizer clean_thread_html_body() used for discussion notification emails fails to remove tags from user-generated discussion post content. This content is rendered with… | ||
| CVE-2024-22209 | Med | 0.00 | 6.4 | 0.01 | Jan 13, 2024 | Open edX Platform is a service-oriented platform for authoring and delivering online learning. A user with a JWT and more limited scopes could call endpoints exceeding their access. This vulnerability has been patched in commit 019888f. |
- risk 0.57cvss 8.8epss 0.01
edx-platform before 2015-07-20 allows code execution by privileged users because the course import endpoint mishandles .tar.gz files.
- risk 0.48cvss 8.5epss 0.00
Open edX Platform enables the authoring and delivery of online learning at any scale. The sync_provider_data endpoint in SAMLProviderDataViewSet allows authenticated Enterprise Admin users to supply an arbitrary URL via the metadata_url POST parameter. This URL is passed…
- risk 0.40cvss 6.1epss 0.01
edx-platform before 2015-09-17 allows XSS via a team name.
- risk 0.35cvss 5.4epss 0.01
edx-platform before 2015-08-17 allows XSS in the Studio listing of courses.
- risk 0.28cvss 5.3epss 0.01
edx-platform before 2016-06-10 allows account activation with a spoofed e-mail address.
- risk 0.27cvss 5.3epss 0.00
Open edX Platform enables the authoring and delivery of online learning at any scale. From the maple release to before the ulmo release, an unauthenticated attacker can fully bypass the email verification process by combining two issues: the OAuth2 password grant issuing tokens…
- risk 0.24cvss 4.7epss —
Open edX Platform enables the authoring and delivery of online learning at any scale. Prior to commit 3a5ac85, a security vulnerability has been identified in the Open edX LMS platform's LTI (Learning Tools Interoperability) Provider implementation. The…
- risk 0.24cvss 4.7epss 0.00
Open edX Platform enables the authoring and delivery of online learning at any scale. The view_survey endpoint accepts a redirect_url GET parameter that is passed directly to HttpResponseRedirect() without any URL validation. When a non-existent survey name is provided, the…
- risk 0.23cvss 4.6epss 0.00
Open edX Platform enables the authoring and delivery of online learning at any scale. The HTML sanitizer clean_thread_html_body() used for discussion notification emails fails to remove tags from user-generated discussion post content. This content is rendered with…
- risk 0.00cvss 6.4epss 0.01
Open edX Platform is a service-oriented platform for authoring and delivering online learning. A user with a JWT and more limited scopes could call endpoints exceeding their access. This vulnerability has been patched in commit 019888f.