VendorsOS4Edopensisany version
Vulnerabilities

OS4Ed openSIS any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

19CVEs
CVE-2020-13381
openSIS through 7.4 allows SQL Injection.
Published 2020-07-01 · Modified
9.8EPSS 0.590
CVE-2020-13380
openSIS before 7.4 allows SQL Injection.
Published 2020-07-01 · Modified
9.8EPSS 0.024
CVE-2021-27341
OpenSIS Community Edition version <= 7.6 is affected by a local file inclusion vulnerability in DownloadWindow.php via the "filename" parameter.
Published 2021-09-16 · Modified
9.8EPSS 0.021
CVE-2025-22926
An issue in OS4ED openSIS v8.0 through v9.1 allows attackers to execute a directory traversal by sending a crafted POST request to /Modules.php?modname=messaging/Inbox.php&modfunc=save&filename.
Published 2025-04-03 · Analyzed
9.8EPSS 0.009
CVE-2025-22930
OS4ED openSIS v7.0 to v9.1 was discovered to contain a SQL injection vulnerability via the groupid parameter at /messaging/Group.php.
Published 2025-04-03 · Analyzed
9.8EPSS 0.005
CVE-2025-22929
OS4ED openSIS v7.0 to v9.1 was discovered to contain a SQL injection vulnerability via the filter_id parameter at /students/StudentFilters.php.
Published 2025-04-03 · Analyzed
9.8EPSS 0.005
CVE-2025-22928
OS4ED openSIS v7.0 to v9.1 was discovered to contain a SQL injection vulnerability via the cp_id parameter at /modules/messages/Inbox.php.
Published 2025-04-03 · Analyzed
9.8EPSS 0.004
CVE-2020-13382
openSIS through 7.4 has Incorrect Access Control.
Published 2020-07-01 · Modified
9.1EPSS 0.528
CVE-2025-22927
An issue in OS4ED openSIS v8.0 through v9.1 allows attackers to execute a directory traversal by sending a crafted POST request to /Modules.php?modname=messaging/Inbox.php&modfunc=save&filename.
Published 2025-04-03 · Analyzed
9.1EPSS 0.008
CVE-2025-22923
An issue in OS4ED openSIS v8.0 through v9.1 allows attackers to execute a directory traversal and delete files by sending a crafted POST request to /Modules.php?modname=users/Staff.php&removefile.
Published 2025-04-02 · Analyzed
8.8EPSS 0.009
CVE-2025-22924
OS4ED openSIS v7.0 through v9.1 contains a SQL injection vulnerability via the stu_id parameter at /modules/students/Student.php.
Published 2025-04-02 · Analyzed
8.8EPSS 0.004
CVE-2025-65594
OpenSIS 9.2 and below is vulnerable to Incorrect Access Control in Student.php, which allows an authenticated low-privilege user to perform unauthorized database write operations relating to the data of other users.
Published 2025-12-09 · Modified
8.1EPSS 0.003
CVE-2020-13383
openSIS through 7.4 allows Directory Traversal.
Published 2020-07-01 · Modified
7.5EPSS 0.678
CVE-2020-27408
OpenSIS Community Edition through 7.6 is affected by incorrect access controls for the file ResetUserInfo.php that allow an unauthenticated attacker to change the password of arbitrary users.
Published 2020-12-04 · Modified
7.5EPSS 0.017
CVE-2025-22931
An insecure direct object reference (IDOR) in the component /assets/stafffiles of OS4ED openSIS v7.0 to v9.1 allows unauthenticated attackers to access files uploaded by staff members.
Published 2025-04-03 · Analyzed
7.5EPSS 0.005
CVE-2025-22925
OS4ED openSIS v7.0 to v9.1 was discovered to contain a SQL injection vulnerability via the table parameter at /attendance/AttendanceCodes.php. The remote, authenticated attacker requires the admin role to successfully exploit this vulnerability.
Published 2025-04-02 · Analyzed
7.5EPSS 0.005
CVE-2022-45962
Open Solutions for Education, Inc openSIS Community Edition v8.0 and earlier is vulnerable to SQL Injection via CalendarModal.php.
Published 2023-02-13 · Modified
6.5EPSS 0.009
CVE-2020-27409
OpenSIS Community Edition before 7.5 is affected by a cross-site scripting (XSS) vulnerability in SideForStudent.php via the modname parameter.
Published 2020-12-04 · Modified
6.1EPSS 0.012
CVE-2021-27340
OpenSIS Community Edition version <= 7.6 is affected by a reflected XSS vulnerability in EmailCheck.php via the "opt" parameter.
Published 2021-09-16 · Modified
6.1EPSS 0.011