VendorsMcGillloris28.0.0
Vulnerabilities

McGill University LORIS (Longitudinal Online Research and Imaging System) 16.0.0 - 28.0.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

9CVEs
CVE-2026-35169
LORIS has potential cross-site scripting in help_editor module
Published 2026-04-08 · Analyzed
8.7EPSS 0.003
CVE-2026-35446
LORIS has a path traversal in FilesDownloadHandler
Published 2026-04-08 · Analyzed
8.6EPSS 0.004
CVE-2026-34392
LORIS has a path traversal in static router
Published 2026-04-08 · Analyzed
7.5EPSS 0.004
CVE-2026-33350
LORIS has a SQL injection in MRI feedback popup
Published 2026-04-08 · Analyzed
7.5EPSS 0.004
CVE-2026-34985
LORIS has incorrect access checks in media module
Published 2026-04-08 · Analyzed
6.5EPSS 0.003
CVE-2026-35165
LORIS has incorrect access checks in document_repository
Published 2026-04-08 · Analyzed
6.5EPSS 0.003
CVE-2026-35403
LORIS has potential cross-site scripting in survey_accounts module
Published 2026-04-08 · Analyzed
6.5EPSS 0.002
CVE-2026-39985
LORIS has an open redirect field on login
Published 2026-04-09 · Analyzed
6.1EPSS 0.003
CVE-2026-35400
LORIS incorrectly trusts user input in publication module
Published 2026-04-08 · Analyzed
4.3EPSS 0.003