İçeriğe atla
Noroxi

openedx kayıtları

openedx üreticisine ait 8 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
0
Düzeltme kaydı olan
%37,5
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

8 kayıt
  • CVE-2024-43782
    39İzleyin

    openedx-translations's Atlas translations for Open edX missing validation

    KritikCVSS 9,8İstismar yokEPSS %1

    openedx · openedx23 Ağu 2024

  • CVE-2026-42858
    39İzleyin

    Open edX Platform: Server-Side Request Forgery (SSRF) in SAML Provider Data Sync Endpoint

    KritikCVSS 9,9İstismar yokEPSS %0

    openedx · openedx11 May 2026

  • CVE-2026-42860
    34İzleyin

    Open edx Enterprise Service: SSRF via SAML metadata URL in sync_provider_data endpoint

    YüksekCVSS 8,5İstismar yokEPSS %0

    openedx · edx-enterprise11 May 2026

  • CVE-2022-46147
    24İzleyin

    Drag and Drop XBlock v2 has XSS Issues in Xblock Input Fields

    OrtaCVSS 6,1İstismar yokEPSS %1

    openedx · xblock-drag-and-drop-v228 Kas 2022

  • CVE-2026-35404
    24İzleyin

    Open edX Platform has an Open Redirect in Survey Views via Unvalidated redirect_url Parameter

    OrtaCVSS 6,1İstismar yokEPSS %0

    openedx · openedx6 Nis 2026

  • CVE-2023-23611
    21İzleyin

    xblock-lti-consumer contain Missing Authorization in Grade Pass Back Implementation

    OrtaCVSS 5,4İstismar yokEPSS %0

    openedx · xblock-lti-consumer26 Oca 2023

  • CVE-2024-41806
    21İzleyin

    Open edX Platform's instructor upload CSV for cohort creation not Private by Default

    OrtaCVSS 5,3İstismar yokEPSS %0

    openedx · edx-platform25 Tem 2024

  • CVE-2026-42857
    21İzleyin

    Open edX Platform: Stored CSS Injection in Email Notifications via Incomplete HTML Sanitization

    OrtaCVSS 5,4İstismar yokEPSS %0

    openedx · openedx11 May 2026