VendorsGUnetopen_eclass_platformall versions
Vulnerabilities

GUnet Open eClass Platform

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

20CVEs
CVE-2020-37113
GUnet OpenEclass 1.7.3 E-learning platform - File Upload Extension Bypass
Published 2026-02-03 · Analyzed
8.8EPSS 0.008
CVE-2020-37116
GUnet OpenEclass 1.7.3 E-learning platform - phpMyAdmin Remote Access
Published 2026-02-03 · Analyzed
8.8EPSS 0.004
CVE-2026-24665
Open eClass is Vulnerable to Stored Cross-Site Scripting (XSS) via Student Assignment Upload
Published 2026-02-03 · Analyzed
8.7EPSS 0.002
CVE-2026-24669
Open eClass Insecure Password Reset Token Reuse Enables Account Takeover
Published 2026-02-03 · Analyzed
7.8EPSS 0.002
CVE-2020-24381
GUnet Open eClass Platform (aka openeclass) before 3.11 might allow remote attackers to read students' submitted assessments because it does not ensure that the web server blocks directory listings, and the data directory is inside the web root by default.
Published 2020-08-19 · Modified
7.5EPSS 0.014
CVE-2026-24773
Open eClass Unauthenticated IDOR Allows Access to Arbitrary User Files
Published 2026-02-03 · Analyzed
7.5EPSS 0.004
CVE-2026-24672
Open eClass is Vulnerable to Stored Cross-Site Scripting (XSS) in User Profile Fields
Published 2026-02-03 · Analyzed
7.3EPSS 0.002
CVE-2020-37112
GUnet OpenEclass 1.7.3 E-learning platform - 'month' SQL Injection
Published 2026-02-03 · Analyzed
7.1EPSS 0.003
CVE-2020-37115
GUnet OpenEclass 1.7.3 E-learning platform - Plaintext Password Storage
Published 2026-02-03 · Analyzed
7.1EPSS 0.003
CVE-2020-37114
GUnet OpenEclass 1.7.3 E-learning platform - Information Disclosure
Published 2026-02-03 · Analyzed
6.5EPSS 0.003
CVE-2026-24668
Open eClass Broken Access Control Allows Students to Add Content to Course Units
Published 2026-02-03 · Analyzed
6.5EPSS 0.002
CVE-2026-24670
Open eClass Has Broken Access Control in Course Units Module Allows Students to Create Units
Published 2026-02-03 · Analyzed
6.5EPSS 0.002
CVE-2026-24666
Open eClass is Vulnerable to CSRF in Teacher-Restricted Endpoints Allows Unauthorized Actions
Published 2026-02-03 · Analyzed
6.5EPSS 0.002
CVE-2021-44266
GUnet Open eClass (aka openeclass) before 3.12.2 allows XSS via the modules/auth/formuser.php auth parameter.
Published 2022-06-11 · Modified
6.1EPSS 0.010
CVE-2026-24671
Open eClass is Vulnerable to Stored Cross-Site Scripting (XSS) in Multiple High-Privilege User Fields
Published 2026-02-03 · Analyzed
6.1EPSS 0.002
CVE-2026-24674
Open eClass is Vulnerable to Reflected Cross-Site Scripting (XSS) in Multiple Endpoints
Published 2026-02-03 · Analyzed
6.1EPSS 0.002
CVE-2026-24664
Open eClass is Vulnerable to Username Enumeration via Login Response Discrepancies
Published 2026-02-03 · Analyzed
5.3EPSS 0.003
CVE-2026-24673
Open eClass Has File Upload Filter Bypass via ZIP Archive Extraction
Published 2026-02-03 · Analyzed
5.3EPSS 0.003
CVE-2026-24667
Open eClass's Active Sessions Not Invalidated After Password Change Allow Persistent Account Access
Published 2026-02-03 · Analyzed
5.0EPSS 0.001
CVE-2026-24774
Open eClass Business Logic Flaw Allows Students to Mark Attendance in Expired Activities
Published 2026-02-03 · Analyzed
4.3EPSS 0.002