Openeclass records
8 published records for vendor openeclass.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 3
- With a fix record
- 12.5%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-434 Unrestricted Upload of File with Dangerous Type4
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
8 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2024-31777Proof of concept | File Upload vulnerability in openeclass v.3.15 and before allows an attacker to execute arbitrary code via a crafted file to the certbadge.popeneclass · openeclass · CWE-434 | Critical9.8 | — | 3.8% | Jun 13, 2024 |
39Monitor | CVE-2024-38530No exploit | Open eClass Platform allows Arbitrary File Upload in "modules/h5p/save.php"openeclass · openeclass · CWE-434 | Critical9.8 | — | 0.8% | Aug 12, 2024 |
36Monitor | CVE-2024-26503Proof of concept | Unrestricted File Upload vulnerability in Greek Universities Network Open eClass v.3.15 and earlier allows attackers to run arbitrary code vopeneclass · openeclass · CWE-434 | Critical9.1 | — | 1.1% | Mar 14, 2024 |
30Monitor | CVE-2026-22241Proof of concept | Open eClass has Unrestricted File Upload that Leads to Remote Code Execution (RCE)openeclass · openeclass · CWE-434 | High7.3 | — | 3.3% | Jan 8, 2026 |
27Monitor | CVE-2022-33116No exploit | An issue in the jmpath variable in /modules/mindmap/index.php of GUnet Open eClass Platform (aka openeclass) v3.12.4 and below allows attackopeneclass · openeclass · CWE-22 | Medium6.5 | — | 1.8% | Jun 27, 2022 |
24Monitor | CVE-2017-7389No exploit | Multiple Cross-Site Scripting (XSS) were discovered in 'openeclass Release_3.5.4'.openeclass · openeclass · CWE-79 | Medium6.1 | — | 0.8% | Mar 31, 2017 |
21Monitor | CVE-2024-33253No exploit | Cross-site scripting (XSS) vulnerability in GUnet OpenEclass E-learning Platform version 3.15 and before allows a authenticated privileged aopeneclass · openeclass · CWE-79 | Medium5.4 | — | 0.4% | Jun 13, 2024 |
21Monitor | CVE-2025-65734No exploit | An authenticated arbitrary file upload vulnerability in the Courses/Work Assignments module of gunet Open eClass v3.11, and fixed in v3.13, openeclass · openeclass · CWE-79 | Medium5.4 | — | 0.2% | Mar 16, 2026 |
- CVE-2024-3177740Plan
File Upload vulnerability in openeclass v.3.15 and before allows an attacker to execute arbitrary code via a crafted file to the certbadge.p
CriticalCVSS 9.8Proof of conceptEPSS 4%openeclass · openeclassJun 13, 2024
- CVE-2024-3853039Monitor
Open eClass Platform allows Arbitrary File Upload in "modules/h5p/save.php"
CriticalCVSS 9.8No exploitEPSS 1%openeclass · openeclassAug 12, 2024
- CVE-2024-2650336Monitor
Unrestricted File Upload vulnerability in Greek Universities Network Open eClass v.3.15 and earlier allows attackers to run arbitrary code v
CriticalCVSS 9.1Proof of conceptEPSS 1%openeclass · openeclassMar 14, 2024
- CVE-2026-2224130Monitor
Open eClass has Unrestricted File Upload that Leads to Remote Code Execution (RCE)
HighCVSS 7.3Proof of conceptEPSS 3%openeclass · openeclassJan 8, 2026
- CVE-2022-3311627Monitor
An issue in the jmpath variable in /modules/mindmap/index.php of GUnet Open eClass Platform (aka openeclass) v3.12.4 and below allows attack
MediumCVSS 6.5No exploitEPSS 2%openeclass · openeclassJun 27, 2022
- CVE-2017-738924Monitor
Multiple Cross-Site Scripting (XSS) were discovered in 'openeclass Release_3.5.4'.
MediumCVSS 6.1No exploitEPSS 1%openeclass · openeclassMar 31, 2017
- CVE-2024-3325321Monitor
Cross-site scripting (XSS) vulnerability in GUnet OpenEclass E-learning Platform version 3.15 and before allows a authenticated privileged a
MediumCVSS 5.4No exploitEPSS 0%openeclass · openeclassJun 13, 2024
- CVE-2025-6573421Monitor
An authenticated arbitrary file upload vulnerability in the Courses/Work Assignments module of gunet Open eClass v3.11, and fixed in v3.13,
MediumCVSS 5.4No exploitEPSS 0%openeclass · openeclassMar 16, 2026