Known Vulnerabilities for products from Edx

Listed below are 19 of the newest known vulnerabilities associated with the vendor "Edx".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2024-22209 json 8.8 - HIGH 2024-01-13 2024-01-22
CVE-2022-32195 json Open edX platform before 2022-06-06 allows XSS via the "next" parameter in the logout URL. 6.1 - MEDIUM 2022-06-09 2022-06-15
CVE-2021-39248 json Open edX through Lilac.1 allows XSS in common/static/common/js/discussion/utils.js via crafted LaTeX content within a discuss... 6.1 - MEDIUM 2021-08-17 2021-08-25
CVE-2020-13146 json Studio in Open edX Ironwood 2.5 allows CSV injection because an added cohort in Course>Instructor>Cohorts may contain a formu... 8.8 - HIGH 2020-05-18 2021-07-21
CVE-2020-13145 json Studio in Open edX Ironwood 2.5 allows users to upload SVG files via the "Content>File Uploads" screen. These files can conta... 5.4 - MEDIUM 2020-05-18 2020-05-20
CVE-2020-13144 json Studio in Open edX Ironwood 2.5, when CodeJail is not used, allows a user to go to the "Create New course>New section>New sub... 8.8 - HIGH 2020-05-18 2022-04-26
CVE-2019-20513 json Open edX Ironwood.1 allows support/certificates?user= reflected XSS. 6.1 - MEDIUM 2020-03-19 2020-03-20
CVE-2018-20859 json edx-platform before 2018-07-18 allows XSS via a response to a Chemical Equation advanced problem. 6.1 - MEDIUM 2019-07-30 2023-11-07
CVE-2018-20858 json Recommender before 2018-07-18 allows XSS. 6.1 - MEDIUM 2019-08-09 2023-11-07
CVE-2017-18381 json The installation process in Open edX before 2017-01-10 exposes a MongoDB instance to external connections with default creden... 7.2 - HIGH 2019-07-30 2023-11-07
CVE-2017-18380 json edx-platform before 2017-08-03 allows attackers to trigger password-reset e-mail messages in which the reset link has an atta... 7.5 - HIGH 2019-07-30 2023-11-07
CVE-2016-10766 json edx-platform before 2016-06-06 allows CSRF. 8.8 - HIGH 2019-07-29 2020-01-07
CVE-2016-10765 json edx-platform before 2016-06-10 allows account activation with a spoofed e-mail address. 5.3 - MEDIUM 2019-07-29 2020-01-07
CVE-2015-6960 json edx-platform before 2015-09-17 allows XSS via a team name. 6.1 - MEDIUM 2019-07-29 2020-01-07
CVE-2015-6671 json Open edX edx-platform before 2015-08-25 requires use of the database for storage of SAML SSO secrets, which makes it easier f... Not Provided 2017-03-13 2025-04-20
CVE-2015-6253 json edx-platform before 2015-08-17 allows XSS in the Studio listing of courses. 5.4 - MEDIUM 2019-07-29 2020-01-07
CVE-2015-5601 json edx-platform before 2015-07-20 allows code execution by privileged users because the course import endpoint mishandles .tar.g... 8.8 - HIGH 2019-07-29 2020-01-07
CVE-2015-2286 json lms/templates/footer-edx-new.html in Open edX edx-platform before 2015-01-29 does not properly restrict links on the password... Not Provided 2016-03-19 2026-05-06
CVE-2015-2186 json The Ansible edxapp role in the Configuration Repo in edX allows remote websites to spoof edX accounts by leveraging use of th... 7.5 - HIGH 2018-02-03 2018-03-02

Known software with vulnerabilities from Edx

Type Vendor Product Version
ApplicationEdxEdx-platform-
ApplicationEdxOpen Edx2015-01-27
ApplicationEdxOpen Edx Platform2.1
ApplicationEdxRecommender-

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report