openedx records
8 published records for vendor openedx.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 37.5%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-918 Server-Side Request Forgery (SSRF)2
- CWE-284 Improper Access Control1
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')1
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')1
- CWE-862 Missing Authorization1
The weakness classes this vendor ships most often: where to look.
CWEAll records
8 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2024-43782No exploit | openedx-translations's Atlas translations for Open edX missing validationopenedx · openedx · CWE-74 | Critical9.8 | — | 0.5% | Aug 23, 2024 |
39Monitor | CVE-2026-42858No exploit | Open edX Platform: Server-Side Request Forgery (SSRF) in SAML Provider Data Sync Endpointopenedx · openedx · CWE-918 | Critical9.9 | — | 0.4% | May 11, 2026 |
34Monitor | CVE-2026-42860No exploit | Open edx Enterprise Service: SSRF via SAML metadata URL in sync_provider_data endpointopenedx · edx-enterprise · CWE-918 | High8.5 | — | 0.3% | May 11, 2026 |
24Monitor | CVE-2022-46147No exploit | Drag and Drop XBlock v2 has XSS Issues in Xblock Input Fieldsopenedx · xblock-drag-and-drop-v2 · CWE-79 | Medium6.1 | — | 0.9% | Nov 28, 2022 |
24Monitor | CVE-2026-35404No exploit | Open edX Platform has an Open Redirect in Survey Views via Unvalidated redirect_url Parameteropenedx · openedx · CWE-601 | Medium6.1 | — | 0.3% | Apr 6, 2026 |
21Monitor | CVE-2023-23611No exploit | xblock-lti-consumer contain Missing Authorization in Grade Pass Back Implementationopenedx · xblock-lti-consumer · CWE-862 | Medium5.4 | — | 0.4% | Jan 26, 2023 |
21Monitor | CVE-2024-41806No exploit | Open edX Platform's instructor upload CSV for cohort creation not Private by Defaultopenedx · edx-platform · CWE-284 | Medium5.3 | — | 0.3% | Jul 25, 2024 |
21Monitor | CVE-2026-42857No exploit | Open edX Platform: Stored CSS Injection in Email Notifications via Incomplete HTML Sanitizationopenedx · openedx · CWE-79 | Medium5.4 | — | 0.3% | May 11, 2026 |
- CVE-2024-4378239Monitor
openedx-translations's Atlas translations for Open edX missing validation
CriticalCVSS 9.8No exploitEPSS 1%openedx · openedxAug 23, 2024
- CVE-2026-4285839Monitor
Open edX Platform: Server-Side Request Forgery (SSRF) in SAML Provider Data Sync Endpoint
CriticalCVSS 9.9No exploitEPSS 0%openedx · openedxMay 11, 2026
- CVE-2026-4286034Monitor
Open edx Enterprise Service: SSRF via SAML metadata URL in sync_provider_data endpoint
HighCVSS 8.5No exploitEPSS 0%openedx · edx-enterpriseMay 11, 2026
- CVE-2022-4614724Monitor
Drag and Drop XBlock v2 has XSS Issues in Xblock Input Fields
MediumCVSS 6.1No exploitEPSS 1%openedx · xblock-drag-and-drop-v2Nov 28, 2022
- CVE-2026-3540424Monitor
Open edX Platform has an Open Redirect in Survey Views via Unvalidated redirect_url Parameter
MediumCVSS 6.1No exploitEPSS 0%openedx · openedxApr 6, 2026
- CVE-2023-2361121Monitor
xblock-lti-consumer contain Missing Authorization in Grade Pass Back Implementation
MediumCVSS 5.4No exploitEPSS 0%openedx · xblock-lti-consumerJan 26, 2023
- CVE-2024-4180621Monitor
Open edX Platform's instructor upload CSV for cohort creation not Private by Default
MediumCVSS 5.3No exploitEPSS 0%openedx · edx-platformJul 25, 2024
- CVE-2026-4285721Monitor
Open edX Platform: Stored CSS Injection in Email Notifications via Incomplete HTML Sanitization
MediumCVSS 5.4No exploitEPSS 0%openedx · openedxMay 11, 2026