Known Vulnerabilities for Opensis by Opensis Project
Listed below are 1 of the newest known vulnerabilities associated with "Opensis" by "Opensis Project".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-11944 json | openSIS Classic 9.3 contains an authenticated path traversal vulnerability in the legacy messaging sent-mail attachment downl... | Not Provided | 2026-07-14 | 2026-07-14 |
| CVE-2026-8406 json | openSIS Classic 9.3 contains an insecure direct object reference vulnerability in the messaging module. Any authenticated use... | Not Provided | 2026-06-11 | 2026-06-11 |
| CVE-2025-65594 json | OpenSIS 9.2 and below is vulnerable to Incorrect Access Control in Student.php, which allows an authenticated low-privilege u... | Not Provided | 2025-12-09 | 2026-07-05 |
| CVE-2024-35584 json | SQL injection vulnerabilities were discovered in Ajax.php, ForWindow.php, ForExport.php, Modules.php, functions/HackingLogFnc... | Not Provided | 2024-10-15 | 2026-07-05 |
| CVE-2021-39378 json | A SQL Injection vulnerability exists in openSIS 8.0 when MySQL (MariaDB) is being used as the application database. A malicio... | 9.8 - CRITICAL | 2021-09-01 | 2021-09-16 |