Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

openedx — Vulnerabilities & Security Advisories 17

Browse all 17 CVE security advisories affecting openedx. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Open edX is an open-source learning management platform used by educational institutions and organizations to deliver online courses. Historically, the platform has been susceptible to various vulnerabilities including remote code execution, cross-site scripting, and privilege escalation, with 9 CVEs currently documented. Security researchers have identified common weaknesses in authentication mechanisms, input validation, and access controls. While no major public security incidents have been widely reported, the platform's open nature requires regular security updates and careful configuration to mitigate risks. Organizations implementing Open edX must prioritize security hardening and continuous monitoring to address potential threats and protect sensitive educational data.

CVE ID Title CVSS Severity Published
CVE-2026-85271 Open edX Platform: Stored CSS Injection in Email Digest Notifications via Unsanitized Thread Title (incomplete patch of CVE-2026-42857) — openedx-platform CWE-79 6.1 Medium 2026-09-18
CVE-2026-85272 Open edX Platform: Path traversal via prefix-bypass in safe_extractall Path Validation — openedx-platform CWE-22 4.3 Medium 2026-09-18
CVE-2026-55421 Open edX Platform: SSRF in Studio Video Download Endpoint — openedx-platform CWE-918 6.8 Medium 2026-09-02
CVE-2026-53636 Open edX LTI OAuth Replay Attack — openedx-platform CWE-294 4.7 Medium 2026-09-02
CVE-2026-53635 Open edX Platform: Insufficient Permission on set_course_mode_price() — openedx-platform CWE-862 7.6 High 2026-09-02
CVE-2026-42860 Open edx Enterprise Service: SSRF via SAML metadata URL in sync_provider_data endpoint — edx-enterprise CWE-918 8.5 High 2026-05-11
CVE-2026-42857 Open edX Platform: Stored CSS Injection in Email Notifications via Incomplete HTML Sanitization — openedx-platform CWE-79 4.6 Medium 2026-05-11
CVE-2026-42858 Open edX Platform: Server-Side Request Forgery (SSRF) in SAML Provider Data Sync Endpoint — openedx-platform CWE-918 8.5 High 2026-05-11
CVE-2026-35404 Open edX Platform has an Open Redirect in Survey Views via Unvalidated redirect_url Parameter — openedx-platform CWE-601 4.7 Medium 2026-04-06
CVE-2026-34736 Open edX Platform: Account Activation Bypass via activation_key Exposure in REST API — openedx-platform CWE-287 5.3 Medium 2026-04-02
CVE-2025-68270 CourseLimitedStaff Role Allows Studio Access — edx-platform CWE-862 9.9 Critical 2025-12-16
CVE-2025-47942 Learners on edX Platform can download python_lib.zip — edx-platform CWE-862 5.3 Medium 2025-05-21
CVE-2024-43782 openedx-translations's Atlas translations for Open edX missing validation — openedx-translations CWE-74 7.7 High 2024-08-23
CVE-2024-41806 Open edX Platform's instructor upload CSV for cohort creation not Private by Default — edx-platform CWE-284 5.3 Medium 2024-07-25
CVE-2024-22209 XBlock custom auth does not respect JWT Scopes — edx-platform CWE-284 6.4 Medium 2024-01-13
CVE-2023-23611 xblock-lti-consumer contain Missing Authorization in Grade Pass Back Implementation — xblock-lti-consumer CWE-862 5.4 Medium 2023-01-25
CVE-2022-46147 Drag and Drop XBlock v2 has XSS Issues in Xblock Input Fields — xblock-drag-and-drop-v2 CWE-79 8.4 High 2022-11-28

This page lists every published CVE security advisory associated with openedx. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.