VendorsFrentixopenolatall versions
Vulnerabilities

Frentix Openolat

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

9CVEs
CVE-2026-31946
OpenOLAT: Authentication bypass via forged JWT in OIDC implicit flow
Published 2026-03-30 · Analyzed
9.8EPSS 0.003
CVE-2021-39180
Path Traversal in Archive Handling Leading to Code Execution
Published 2021-08-31 · Modified
9.0EPSS 0.024
CVE-2021-39181
Unsafe Deserialization of User Data Using XStream
Published 2021-09-01 · Modified
8.8EPSS 0.019
CVE-2026-28228
OpenOLAT: Server-Side Template Injection (SSTI) in Velocity templates allows Remote Code Execution
Published 2026-03-30 · Analyzed
8.8EPSS 0.005
CVE-2021-41242
Path Traversal in some REST methods leading to file upload to arbitrary places
Published 2021-12-10 · Modified
8.1EPSS 0.014
CVE-2021-41152
Path Traversal in Folder Component Leading to Local File Inclusion
Published 2021-10-18 · Modified
7.7EPSS 0.012
CVE-2024-28198
XML external entity (XXE) injection in OpenOLAT
Published 2024-03-11 · Analyzed
7.5EPSS 0.004
CVE-2024-25973
Multiple Stored Cross-Site Scripting Vulnerabilities
Published 2024-02-20 · Modified
5.4EPSS 0.006
CVE-2024-25974
Stored Cross-Site Scripting (XSS) within the Media Center
Published 2024-02-20 · Analyzed
5.4EPSS 0.006