Known Vulnerabilities for products from Evergreen-ils
Listed below are 3 of the newest known vulnerabilities associated with the vendor "Evergreen-ils".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2025-67622 json | Not Provided | 2025-12-24 | 2026-04-27 | |
| CVE-2025-64234 json | Not Provided | 2025-10-29 | 2026-04-27 | |
| CVE-2025-49373 json | Not Provided | 2025-10-22 | 2026-04-27 | |
| CVE-2024-29099 json | Not Provided | 2024-03-19 | 2026-04-28 | |
| CVE-2023-51423 json | Not Provided | 2023-12-31 | 2026-04-28 | |
| CVE-2023-51422 json | Not Provided | 2023-12-29 | 2026-04-28 | |
| CVE-2023-41127 json | Not Provided | 2023-11-30 | 2026-04-28 | |
| CVE-2015-2204 json | Evergreen before 2.5.9, 2.6.x before 2.6.7, and 2.7.x before 2.7.4 allows remote attackers to bypass an intended access restr... | 7.5 - HIGH | 2018-02-01 | 2023-11-07 |
| CVE-2015-2203 json | Evergreen 2.5.9, 2.6.7, and 2.7.4 allows remote authenticated users with STAFF_LOGIN permission to obtain sensitive settings ... | 6.5 - MEDIUM | 2018-02-01 | 2023-11-07 |
| CVE-2013-7435 json | The open-ils.pcrud endpoint in Evergreen before 2.5.9, 2.6.x before 2.6.7, and 2.7.x before 2.7.4 allows remote attackers to ... | 6.5 - MEDIUM | 2018-02-01 | 2023-11-07 |
Known software with vulnerabilities from Evergreen-ils
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Evergreen-ils | Evergreen | 2.5.7 |