Products: 5
    Vulnerabilities: 24
    Known Exploited: 0
    0
    Critical Level Threats
    7
    High Level Threats
    16
    Medium Level Threats
    1
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2012-5776

    Dokeos 2.1.1 has multiple XSS issues involving "extra_" parameters in main/auth/profile.php.

    Last Modified: Nov 21, 2024
    Published: Jan 29, 2020

    CVE-2013-6341

    SQL injection vulnerability in Dokeos 2.2 RC2 and earlier allows remote attackers to execute arbitrary SQL commands via the language parameter to index.php.

    Last Modified: Apr 11, 2025
    Published: Dec 05, 2013

    CVE-2009-2007

    Multiple directory traversal vulnerabilities in Dokeos 1.8.5, and possibly earlier, allow remote attackers to (1) read portions of arbitrary files via a .. (dot dot) and a ..\ (dot dot backslash) in the lang parameter to main/exercice/hotspot_lang_conversion.php and (2) read arbitrary files via a .. (dot dot) in the doc_url parameter to main/exercice/Hpdownload.php.

    Last Modified: Apr 23, 2026
    Published: Jun 08, 2009

    CVE-2009-2004

    Multiple SQL injection vulnerabilities in main/mySpace/myStudents.php in Dokeos 1.8.5, and possibly earlier, allow remote attackers to execute arbitrary SQL commands via the (1) student and (2) course parameters, a different vector than CVE-2007-2902.

    Last Modified: Apr 23, 2026
    Published: Jun 08, 2009

    CVE-2009-2005

    Cross-site request forgery (CSRF) vulnerability in Dokeos 1.8.5, and possibly earlier, allows remote attackers to hijack the authentication of unspecified victims and add new personal agenda items via unknown vectors.

    Last Modified: Apr 23, 2026
    Published: Jun 08, 2009
    Items Per Page
    Dokeos Vulnerabilities & Security CVEs | CVE-DB