Known Vulnerabilities for products from ILIAS
Listed below are 20 of the newest known vulnerabilities associated with the vendor "ILIAS".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-86416 json | Not Provided | 2026-09-07 | 2026-09-18 | |
| CVE-2026-85135 json | Not Provided | 2026-09-03 | 2026-09-03 | |
| CVE-2026-82877 json | Not Provided | 2026-08-31 | 2026-09-30 | |
| CVE-2026-82538 json | Not Provided | 2026-09-04 | 2026-09-30 | |
| CVE-2026-80428 json | Not Provided | 2026-08-26 | 2026-09-30 | |
| CVE-2026-12789 json | Not Provided | 2026-06-21 | 2026-07-15 | |
| CVE-2023-45869 json | ILIAS 7.25 (2023-09-12) allows any authenticated user to execute arbitrary operating system commands remotely, when a highly ... | 9 - CRITICAL | 2023-10-26 | 2023-11-14 |
| CVE-2023-45868 json | The Learning Module in ILIAS 7.25 (2023-09-12 release) allows an attacker (with basic user privileges) to achieve a high-impa... | 6.5 - MEDIUM | 2023-10-26 | 2023-11-14 |
| CVE-2023-45867 json | ILIAS (2013-09-12 release) contains a medium-criticality Directory Traversal local file inclusion vulnerability in the ScormA... | 6.5 - MEDIUM | 2023-10-26 | 2023-11-14 |
| CVE-2023-36488 json | ILIAS 7.21 and 8.0_beta1 through 8.2 is vulnerable to stored Cross Site Scripting (XSS). | 5.4 - MEDIUM | 2023-06-29 | 2023-07-07 |
| CVE-2023-36487 json | The password reset function in ILIAS 7.0_beta1 through 7.20 and 8.0_beta1 through 8.1 allows remote attackers to take over th... | 9.8 - CRITICAL | 2023-06-29 | 2023-07-06 |
| CVE-2023-36486 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 8.8 - HIGH | 2023-12-25 | 2024-01-03 |
| CVE-2023-36485 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 8.8 - HIGH | 2023-12-25 | 2024-01-03 |
| CVE-2023-36484 json | ILIAS 7.21 and 8.0_beta1 through 8.2 is vulnerable to reflected Cross-Site Scripting (XSS). | 6.1 - MEDIUM | 2023-06-29 | 2023-07-07 |
| CVE-2023-32778 json | Not Provided | 2026-09-14 | 2026-09-16 | |
| CVE-2022-45918 json | ILIAS before 7.16 allows External Control of File Name or Path. | 6.5 - MEDIUM | 2022-12-07 | 2023-08-08 |
| CVE-2022-45917 json | ILIAS before 7.16 has an Open Redirect. | 6.1 - MEDIUM | 2022-12-07 | 2023-01-06 |
| CVE-2022-45916 json | ILIAS before 7.16 allows XSS. | 5.4 - MEDIUM | 2022-12-07 | 2023-01-06 |
| CVE-2022-45915 json | ILIAS before 7.16 allows OS Command Injection. | 8.8 - HIGH | 2022-12-07 | 2023-01-06 |
| CVE-2022-31266 json | In ILIAS through 7.10, lack of verification when changing an email address (on the Profile Page) allows remote attackers to t... | 9.8 - CRITICAL | 2022-06-29 | 2023-11-07 |
Known software with vulnerabilities from ILIAS
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Ilias | Ilias | 2.4.7 |