VYPR
Vendor

Open.edx

Products
9
CVEs
24
Across products
31
Status
Private

Products

9

Recent CVEs

24
View all 24 CVEs →
  • CVE-2025-68270CriDec 16, 2025
    risk 0.64cvss 9.9epss 0.00

    The Open edX Platform is a learning management platform. Prior to commit 05d0d0936daf82c476617257aa6c35f0cd4ca060, CourseLimitedStaffRole users are able to access and edit courses in studio if they are granted the role on an org rather than on a course, and…

  • CVE-2020-13144HigMay 18, 2020
    risk 0.61cvss 8.8epss 0.11

    Studio in Open edX Ironwood 2.5, when CodeJail is not used, allows a user to go to the "Create New course>New section>New subsection>New unit>Add new component>Problem button>Advanced tab>Custom Python evaluated code" screen, edit the problem, and execute Python code. This leads…

  • CVE-2025-69784HigMar 16, 2026
    risk 0.57cvss 8.8epss 0.00

    A local, non-privileged attacker can abuse a vulnerable IOCTL interface exposed by the OpenEDR 2.5.1.0 kernel driver to modify the DLL injection path used by the product. By redirecting this path to a user-writable location, an attacker can cause OpenEDR to load an…

  • CVE-2020-13146HigMay 18, 2020
    risk 0.57cvss 8.8epss 0.01

    Studio in Open edX Ironwood 2.5 allows CSV injection because an added cohort in Course>Instructor>Cohorts may contain a formula that is exported via the "Course>Data Downloads>Reports>Download profile info" feature.

  • CVE-2025-69783HigMar 16, 2026
    risk 0.51cvss 7.8epss 0.00

    A local attacker can bypass OpenEDR's 2.5.1.0 self-defense mechanism by renaming a malicious executable to match a trusted process name (e.g., csrss.exe, edrsvc.exe, edrcon.exe). This allows unauthorized interaction with the OpenEDR kernel driver, granting access to privileged…

  • CVE-2026-42860HigMay 11, 2026
    risk 0.48cvss 8.5epss 0.00

    The Open edx Enterprise Service app provides enterprise features to the Open edX platform. From 7.0.2 to 7.0.4, the sync_provider_data endpoint in SAMLProviderDataViewSet fetches SAML metadata from a URL stored in SAMLProviderConfig.metadata_source. An authenticated user with…

  • CVE-2026-42858HigMay 11, 2026
    risk 0.48cvss 8.5epss 0.00

    Open edX Platform enables the authoring and delivery of online learning at any scale. The sync_provider_data endpoint in SAMLProviderDataViewSet allows authenticated Enterprise Admin users to supply an arbitrary URL via the metadata_url POST parameter. This URL is passed…

  • CVE-2022-46147HigNov 28, 2022
    risk 0.48cvss 8.4epss 0.01

    Drag and Drop XBlock v2 implements a drag-and-drop style problem, where a learner has to drag items to zones on a target image. Versions prior to 3.0.0 are vulnerable to cross-site scripting in multiple XBlock Fields. Any platform that has deployed the XBlock may be impacted.…

  • CVE-2017-18381HigJul 30, 2019
    risk 0.47cvss 7.2epss 0.01

    The installation process in Open edX before 2017-01-10 exposes a MongoDB instance to external connections with default credentials.

  • CVE-2024-52452HigDec 2, 2024
    risk 0.46cvss 7.1epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in eduNEXT Open edX LMS allows Reflected XSS.This issue affects Open edX LMS: from n/a through 2.6.1.

  • CVE-2022-32195MedJun 9, 2022
    risk 0.40cvss 6.1epss 0.02

    Open edX platform before 2022-06-06 allows XSS via the "next" parameter in the logout URL.

  • CVE-2021-39248MedAug 17, 2021
    risk 0.40cvss 6.1epss 0.01

    Open edX through Lilac.1 allows XSS in common/static/common/js/discussion/utils.js via crafted LaTeX content within a discussion.

  • CVE-2019-20513MedMar 19, 2020
    risk 0.40cvss 6.1epss 0.00

    Open edX Ironwood.1 allows support/certificates?user= reflected XSS.

  • CVE-2019-20512MedMar 18, 2020
    risk 0.40cvss 6.1epss 0.00

    Open edX Ironwood.1 allows support/certificates?course_id= reflected XSS.

  • CVE-2015-6671MedMar 13, 2017
    risk 0.38cvss 5.9epss 0.01

    Open edX edx-platform before 2015-08-25 requires use of the database for storage of SAML SSO secrets, which makes it easier for context-dependent attackers to obtain sensitive information by leveraging access to a database backup.

  • CVE-2020-13145MedMay 18, 2020
    risk 0.35cvss 5.4epss 0.01

    Studio in Open edX Ironwood 2.5 allows users to upload SVG files via the "Content>File Uploads" screen. These files can contain JavaScript code and thus lead to Stored XSS.

  • CVE-2023-23611MedJan 26, 2023
    risk 0.28cvss 5.4epss 0.00

    LTI Consumer XBlock implements the consumer side of the LTI specification enabling integration of third-party LTI provider tools. Versions 7.0.0 and above, prior to 7.2.2, are vulnerable to Missing Authorization. Any LTI tool that is integrated with on the Open edX platform can…

  • CVE-2026-34736MedApr 2, 2026
    risk 0.27cvss 5.3epss 0.00

    Open edX Platform enables the authoring and delivery of online learning at any scale. From the maple release to before the ulmo release, an unauthenticated attacker can fully bypass the email verification process by combining two issues: the OAuth2 password grant issuing tokens…

  • CVE-2025-47942MedMay 21, 2025
    risk 0.27cvss 5.3epss 0.00

    The Open edX Platform is a learning management platform. Prior to commit 6740e75c0fdc7ba095baf88e9f5e4f3e15cfd8ba, edxapp has no built-in protection against downloading the python_lib.zip asset from courses, which is a concern since it often contains custom grading code or…

  • CVE-2024-41806MedJul 25, 2024
    risk 0.27cvss 5.3epss 0.00

    The Open edX Platform is a learning management platform. Instructors can upload csv files containing learner information to create cohorts in the instructor dashboard. These files are uploaded using the django default storage. With certain storage backends, uploads may become…