Skip to content
Noroxi

openedx records

8 published records for vendor openedx.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
37.5%
Median publish → KEV
No record has entered KEV

All records

8 records
  • openedx-translations's Atlas translations for Open edX missing validation

    CriticalCVSS 9.8No exploitEPSS 1%

    openedx · openedxAug 23, 2024

  • Open edX Platform: Server-Side Request Forgery (SSRF) in SAML Provider Data Sync Endpoint

    CriticalCVSS 9.9No exploitEPSS 0%

    openedx · openedxMay 11, 2026

  • Open edx Enterprise Service: SSRF via SAML metadata URL in sync_provider_data endpoint

    HighCVSS 8.5No exploitEPSS 0%

    openedx · edx-enterpriseMay 11, 2026

  • Drag and Drop XBlock v2 has XSS Issues in Xblock Input Fields

    MediumCVSS 6.1No exploitEPSS 1%

    openedx · xblock-drag-and-drop-v2Nov 28, 2022

  • Open edX Platform has an Open Redirect in Survey Views via Unvalidated redirect_url Parameter

    MediumCVSS 6.1No exploitEPSS 0%

    openedx · openedxApr 6, 2026

  • xblock-lti-consumer contain Missing Authorization in Grade Pass Back Implementation

    MediumCVSS 5.4No exploitEPSS 0%

    openedx · xblock-lti-consumerJan 26, 2023

  • Open edX Platform's instructor upload CSV for cohort creation not Private by Default

    MediumCVSS 5.3No exploitEPSS 0%

    openedx · edx-platformJul 25, 2024

  • Open edX Platform: Stored CSS Injection in Email Notifications via Incomplete HTML Sanitization

    MediumCVSS 5.4No exploitEPSS 0%

    openedx · openedxMay 11, 2026