VendorsApereoopencastall versions
Vulnerabilities

Apereo Opencast

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

20CVEs
CVE-2020-5206
Authentication Bypass For Endpoints With Anonymous Access in OpenCast
Published 2020-01-30 · Modified
10.0EPSS 0.013
CVE-2021-43821
Files Accessible to External Parties in Opencast
Published 2021-12-14 · Modified
9.9EPSS 0.020
CVE-2020-5222
Hard-Coded Key Used For Remember-me Token in OpenCast
Published 2020-01-30 · Modified
8.8EPSS 0.009
CVE-2021-32623
Opencast vulnerable to billion laughs attack (XML bomb)
Published 2021-06-15 · Modified
8.1EPSS 0.013
CVE-2020-5229
Opencast stores passwords using outdated MD5 hash algorithm
Published 2020-01-30 · Modified
8.1EPSS 0.006
CVE-2020-5230
Opencast uses unsafe identifiers
Published 2020-01-30 · Modified
7.7EPSS 0.012
CVE-2020-5228
Opencast allows unauthorized public access via OAI-PMH
Published 2020-01-30 · Modified
7.6EPSS 0.010
CVE-2021-43807
HTTP Method Spoofing in Opencast
Published 2021-12-14 · Modified
7.5EPSS 0.014
CVE-2024-52797
Searching Opencast may cause a denial of service
Published 2024-11-21 · Modified
7.5EPSS 0.009
CVE-2018-16153
An issue was discovered in Apereo Opencast 4.x through 10.x before 10.6. It sends system digest credentials during authentication attempts to arbitrary external services in some situations.
Published 2023-12-12 · Modified
7.5EPSS 0.008
CVE-2017-1000221
In Opencast 2.2.3 and older if user names overlap, the Opencast search service used for publication to the media modules and players will handle the access control incorrectly so that users only need to match part of the user name used for the access restriction. For example, a user with the role ROLE_USER will have access to recordings published only for ROLE_USER_X.
Published 2017-11-17 · Modified
6.5EPSS 0.008
CVE-2020-5231
Opencast users with ROLE_COURSE_ADMIN can create new users
Published 2020-01-30 · Modified
6.5EPSS 0.006
CVE-2025-54380
Opencast still publishes global system account credentials
Published 2025-07-26 · Analyzed
6.5EPSS 0.004
CVE-2022-41965
Opencast Authenticated OpenRedirect Vulnerability
Published 2022-11-28 · Modified
6.1EPSS 0.004
CVE-2021-21318
Removing access may not effect published series
Published 2021-02-18 · Modified
5.5EPSS 0.007
CVE-2022-29237
Limited Authentication Bypass for Media Files in Opencast
Published 2022-05-24 · Modified
5.5EPSS 0.006
CVE-2025-61788
Opencast Paella Player 7 vulnerable to Cross-Site-Scripting
Published 2025-10-08 · Analyzed
5.4EPSS 0.002
CVE-2025-55202
Opencast has a partial path traversal vulnerability in UI config
Published 2025-08-29 · Analyzed
5.3EPSS 0.004
CVE-2020-26234
Disabled Hostname Verification in OpenCast
Published 2020-12-08 · Modified
4.8EPSS 0.003
CVE-2025-61906
Opencast's editor accidentally publishes videos/overwrites publications #1626
Published 2025-10-08 · Analyzed
4.3EPSS 0.003