VendorsInstructurecanvas_learning_management_serviceall versions
Vulnerabilities

Instructure Canvas Learning Management Service

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2021-36539
Instructure Canvas LMS didn't properly deny access to locked/unpublished files when the unprivileged user access the DocViewer based file preview URL (canvadoc_session_url).
Published 2023-01-26 · Modified
6.5EPSS 0.009
CVE-2020-5775
Server-Side Request Forgery in Canvas LMS 2020-07-29 allows a remote, unauthenticated attacker to cause the Canvas application to perform HTTP GET requests to arbitrary domains.
Published 2020-08-21 · Modified
5.8EPSS 0.065