Products: 2
    Vulnerabilities: 82
    Known Exploited: 0
    31
    Critical Level Threats
    39
    High Level Threats
    10
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-11944

    openSIS Classic 9.3 - Authenticated path traversal in SentMail attachment download

    Last Modified: Jul 14, 2026
    Published: Jul 14, 2026

    CVE-2026-8406

    openSIS Classic 9.3 - Insecure Direct Object Reference in Sent Mail

    Last Modified: Jun 11, 2026
    Published: Jun 11, 2026

    CVE-2025-65594

    OpenSIS 9.2 and below is vulnerable to Incorrect Access Control in Student.php, which allows an authenticated low-privilege user to perform unauthorized database write operations relating to the data of other users.

    Last Modified: Dec 11, 2025
    Published: Dec 09, 2025

    CVE-2025-26186

    SQL Injection vulnerability in openSIS v.9.1 allows a remote attacker to execute arbitrary code via the id parameter in Ajax.php

    Last Modified: Jul 17, 2025
    Published: Jul 15, 2025

    CVE-2021-41691

    A SQL injection vulnerability exists in OS4Ed Open Source Information System Community v8.0 via the "student_id" and "TRANSFER{SCHOOL]" parameters in POST request sent to /TransferredOutModal.php.

    Last Modified: Jul 09, 2025
    Published: Jun 24, 2025
    Items Per Page