VendorsGUnetopen_eclass_platformany version
Vulnerabilities

GUnet Open eClass Platform any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

15CVEs
CVE-2026-24665
Open eClass is Vulnerable to Stored Cross-Site Scripting (XSS) via Student Assignment Upload
Published 2026-02-03 · Analyzed
8.7EPSS 0.002
CVE-2026-24669
Open eClass Insecure Password Reset Token Reuse Enables Account Takeover
Published 2026-02-03 · Analyzed
7.8EPSS 0.002
CVE-2020-24381
GUnet Open eClass Platform (aka openeclass) before 3.11 might allow remote attackers to read students' submitted assessments because it does not ensure that the web server blocks directory listings, and the data directory is inside the web root by default.
Published 2020-08-19 · Modified
7.5EPSS 0.014
CVE-2026-24773
Open eClass Unauthenticated IDOR Allows Access to Arbitrary User Files
Published 2026-02-03 · Analyzed
7.5EPSS 0.004
CVE-2026-24672
Open eClass is Vulnerable to Stored Cross-Site Scripting (XSS) in User Profile Fields
Published 2026-02-03 · Analyzed
7.3EPSS 0.002
CVE-2026-24668
Open eClass Broken Access Control Allows Students to Add Content to Course Units
Published 2026-02-03 · Analyzed
6.5EPSS 0.002
CVE-2026-24670
Open eClass Has Broken Access Control in Course Units Module Allows Students to Create Units
Published 2026-02-03 · Analyzed
6.5EPSS 0.002
CVE-2026-24666
Open eClass is Vulnerable to CSRF in Teacher-Restricted Endpoints Allows Unauthorized Actions
Published 2026-02-03 · Analyzed
6.5EPSS 0.002
CVE-2021-44266
GUnet Open eClass (aka openeclass) before 3.12.2 allows XSS via the modules/auth/formuser.php auth parameter.
Published 2022-06-11 · Modified
6.1EPSS 0.010
CVE-2026-24671
Open eClass is Vulnerable to Stored Cross-Site Scripting (XSS) in Multiple High-Privilege User Fields
Published 2026-02-03 · Analyzed
6.1EPSS 0.002
CVE-2026-24674
Open eClass is Vulnerable to Reflected Cross-Site Scripting (XSS) in Multiple Endpoints
Published 2026-02-03 · Analyzed
6.1EPSS 0.002
CVE-2026-24664
Open eClass is Vulnerable to Username Enumeration via Login Response Discrepancies
Published 2026-02-03 · Analyzed
5.3EPSS 0.003
CVE-2026-24673
Open eClass Has File Upload Filter Bypass via ZIP Archive Extraction
Published 2026-02-03 · Analyzed
5.3EPSS 0.003
CVE-2026-24667
Open eClass's Active Sessions Not Invalidated After Password Change Allow Persistent Account Access
Published 2026-02-03 · Analyzed
5.0EPSS 0.001
CVE-2026-24774
Open eClass Business Logic Flaw Allows Students to Mark Attendance in Expired Activities
Published 2026-02-03 · Analyzed
4.3EPSS 0.002