← Back

Edx

edx

19 CVEs • 5 products

Products (5)

Click to collapse
Toggle
Edx Platform
edx-platform
Open Edx
open_edx
Configuration
configuration
Recommender
recommender

CVEs (19)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Edx
1Edx Platform
Jun 17, 2026
Jan 13, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Open edX Platform is a service-oriented platform for authoring and delivering online learning. A user with a JWT and more limited scopes could call endpoints exceeding their access. This vulnerability has been patched in...Show more
Open edX Platform is a service-oriented platform for authoring and delivering online learning. A user with a JWT and more limited scopes could call endpoints exceeding their access. This vulnerability has been patched in commit 019888f.Show less
1Edx
1Open Edx
Jun 17, 2026
Jun 9, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Open edX platform before 2022-06-06 allows XSS via the "next" parameter in the logout URL.
1Edx
1Edx Platform
Jun 17, 2026
Aug 17, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Open edX through Lilac.1 allows XSS in common/static/common/js/discussion/utils.js via crafted LaTeX content within a discussion.
1Edx
1Open Edx Platform
Jun 17, 2026
May 18, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Studio in Open edX Ironwood 2.5 allows CSV injection because an added cohort in Course>Instructor>Cohorts may contain a formula that is exported via the "Course>Data Downloads>Reports>Download profile info" feature.
1Edx
1Open Edx Platform
Jun 17, 2026
May 18, 2020
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Studio in Open edX Ironwood 2.5 allows users to upload SVG files via the "Content>File Uploads" screen. These files can contain JavaScript code and thus lead to Stored XSS.
1Edx
1Open Edx Platform
Jun 17, 2026
May 18, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Studio in Open edX Ironwood 2.5, when CodeJail is not used, allows a user to go to the "Create New course>New section>New subsection>New unit>Add new component>Problem button>Advanced tab>Custom Python evaluated code" sc...Show more
Studio in Open edX Ironwood 2.5, when CodeJail is not used, allows a user to go to the "Create New course>New section>New subsection>New unit>Add new component>Problem button>Advanced tab>Custom Python evaluated code" screen, edit the problem, and execute Python code. This leads to arbitrary code execution.Show less
1Edx
1Open Edx
Jun 17, 2026
Mar 19, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Open edX Ironwood.1 allows support/certificates?user= reflected XSS.
1Edx
1Recommender
Nov 21, 2024
Aug 9, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Recommender before 2018-07-18 allows XSS.
1Edx
1Edx Platform
Nov 21, 2024
Jul 30, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
edx-platform before 2018-07-18 allows XSS via a response to a Chemical Equation advanced problem.
1Edx
1Edx Platform
Nov 21, 2024
Jul 30, 2019
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
The installation process in Open edX before 2017-01-10 exposes a MongoDB instance to external connections with default credentials.
1Edx
1Edx Platform
Nov 21, 2024
Jul 30, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
edx-platform before 2017-08-03 allows attackers to trigger password-reset e-mail messages in which the reset link has an attacker-controlled domain name.
1Edx
1Edx Platform
Nov 21, 2024
Jul 29, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
edx-platform before 2016-06-06 allows CSRF.
1Edx
1Edx Platform
Nov 21, 2024
Jul 29, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
edx-platform before 2016-06-10 allows account activation with a spoofed e-mail address.
1Edx
1Edx Platform
Nov 21, 2024
Jul 29, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
edx-platform before 2015-09-17 allows XSS via a team name.
1Edx
1Edx Platform
Nov 21, 2024
Jul 29, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
edx-platform before 2015-08-17 allows XSS in the Studio listing of courses.
1Edx
1Edx Platform
Nov 21, 2024
Jul 29, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
edx-platform before 2015-07-20 allows code execution by privileged users because the course import endpoint mishandles .tar.gz files.
1Edx
2Configuration
Edx Platform
Nov 21, 2024
Feb 3, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The Ansible edxapp role in the Configuration Repo in edX allows remote websites to spoof edX accounts by leveraging use of the string literal "False" instead of a boolean False for the CORS_ORIGIN_ALLOW_ALL setting. Note...Show more
The Ansible edxapp role in the Configuration Repo in edX allows remote websites to spoof edX accounts by leveraging use of the string literal "False" instead of a boolean False for the CORS_ORIGIN_ALLOW_ALL setting. Note: this vulnerability was fixed on 2015-03-06, but the version number was not changed.Show less
1Edx
1Edx Platform
May 13, 2026
Mar 13, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
Open edX edx-platform before 2015-08-25 requires use of the database for storage of SAML SSO secrets, which makes it easier for context-dependent attackers to obtain sensitive information by leveraging access to a databa...Show more
Open edX edx-platform before 2015-08-25 requires use of the database for storage of SAML SSO secrets, which makes it easier for context-dependent attackers to obtain sensitive information by leveraging access to a database backup.Show less
1Edx
1Open Edx
May 6, 2026
Mar 19, 2016
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
lms/templates/footer-edx-new.html in Open edX edx-platform before 2015-01-29 does not properly restrict links on the password-reset page, which allows user-assisted remote attackers to discover password-reset tokens by r...Show more
lms/templates/footer-edx-new.html in Open edX edx-platform before 2015-01-29 does not properly restrict links on the password-reset page, which allows user-assisted remote attackers to discover password-reset tokens by reading a referer log after a victim navigates from this page to a social-sharing site.Show less